<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Scoping Questionnaire - CloudGuard WAF in WAF</title>
    <link>https://community.checkpoint.com/t5/WAF/Scoping-Questionnaire-CloudGuard-WAF/m-p/255354#M338</link>
    <description>&lt;P&gt;For CloudGuard WAF deployments, we have a section in the documentation that covers the information we would need to deploy.&lt;BR /&gt;Not sure if that's exactly what you're looking for, but perhaps it will help:&amp;nbsp;&lt;A href="https://waf-doc.inext.checkpoint.com/getting-started/prepare-key-information" target="_blank"&gt;https://waf-doc.inext.checkpoint.com/getting-started/prepare-key-information&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 18 Aug 2025 15:51:24 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-08-18T15:51:24Z</dc:date>
    <item>
      <title>Scoping Questionnaire - CloudGuard WAF</title>
      <link>https://community.checkpoint.com/t5/WAF/Scoping-Questionnaire-CloudGuard-WAF/m-p/255288#M337</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Does anybody have a scoping questionnaire for&lt;STRONG&gt; ClodGuard WAF Agent (VMware)&lt;/STRONG&gt; to understand the customer requirement?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Aug 2025 19:20:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/Scoping-Questionnaire-CloudGuard-WAF/m-p/255288#M337</guid>
      <dc:creator>Ash-Hal</dc:creator>
      <dc:date>2025-08-17T19:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: Scoping Questionnaire - CloudGuard WAF</title>
      <link>https://community.checkpoint.com/t5/WAF/Scoping-Questionnaire-CloudGuard-WAF/m-p/255354#M338</link>
      <description>&lt;P&gt;For CloudGuard WAF deployments, we have a section in the documentation that covers the information we would need to deploy.&lt;BR /&gt;Not sure if that's exactly what you're looking for, but perhaps it will help:&amp;nbsp;&lt;A href="https://waf-doc.inext.checkpoint.com/getting-started/prepare-key-information" target="_blank"&gt;https://waf-doc.inext.checkpoint.com/getting-started/prepare-key-information&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2025 15:51:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/Scoping-Questionnaire-CloudGuard-WAF/m-p/255354#M338</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-08-18T15:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: Scoping Questionnaire - CloudGuard WAF</title>
      <link>https://community.checkpoint.com/t5/WAF/Scoping-Questionnaire-CloudGuard-WAF/m-p/255357#M339</link>
      <description>&lt;P&gt;Apart from what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;had sent, here is something additional that can also help.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;H2 data-start="318" data-end="376"&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; CloudGuard WAF Agent (VMware) – Scoping Questionnaire&lt;/H2&gt;
&lt;H3 data-start="378" data-end="409"&gt;1. &lt;STRONG data-start="385" data-end="409"&gt;Customer Environment&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL data-start="410" data-end="794"&gt;
&lt;LI data-start="410" data-end="484"&gt;
&lt;P data-start="412" data-end="484"&gt;What is the current VMware version and edition (vSphere, ESXi, vCenter)?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="485" data-end="552"&gt;
&lt;P data-start="487" data-end="552"&gt;How many ESXi hosts and clusters are in scope for WAF deployment?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="553" data-end="651"&gt;
&lt;P data-start="555" data-end="651"&gt;Are there any existing Check Point products in use (e.g., CloudGuard Network, Harmony Endpoint)?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="652" data-end="720"&gt;
&lt;P data-start="654" data-end="720"&gt;What is the expected traffic volume (peak and average throughput)?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="721" data-end="794"&gt;
&lt;P data-start="723" data-end="794"&gt;Are applications hosted in a single datacenter or multiple datacenters?&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3 data-start="796" data-end="828"&gt;2. &lt;STRONG data-start="803" data-end="828"&gt;Applications in Scope&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL data-start="829" data-end="1191"&gt;
&lt;LI data-start="829" data-end="875"&gt;
&lt;P data-start="831" data-end="875"&gt;Which web applications need to be protected?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="876" data-end="948"&gt;
&lt;P data-start="878" data-end="948"&gt;What are the application platforms (IIS, Apache, Nginx, Tomcat, etc.)?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="949" data-end="1003"&gt;
&lt;P data-start="951" data-end="1003"&gt;Are applications containerized, VM-based, or hybrid?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1004" data-end="1059"&gt;
&lt;P data-start="1006" data-end="1059"&gt;Do applications use APIs (REST, SOAP, GraphQL, JSON)?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1060" data-end="1125"&gt;
&lt;P data-start="1062" data-end="1125"&gt;Are applications internal, external (internet-facing), or both?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1126" data-end="1191"&gt;
&lt;P data-start="1128" data-end="1191"&gt;Are there compliance requirements (PCI DSS, HIPAA, GDPR, etc.)?&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3 data-start="1193" data-end="1229"&gt;3. &lt;STRONG data-start="1200" data-end="1229"&gt;Networking &amp;amp; Traffic Flow&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL data-start="1230" data-end="1579"&gt;
&lt;LI data-start="1230" data-end="1323"&gt;
&lt;P data-start="1232" data-end="1323"&gt;How is traffic currently routed to the applications (Load Balancer, Reverse Proxy, Direct)?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1324" data-end="1406"&gt;
&lt;P data-start="1326" data-end="1406"&gt;Where will the WAF Agent be deployed in the network path (inline, TAP, sidecar)?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1407" data-end="1471"&gt;
&lt;P data-start="1409" data-end="1471"&gt;Are SSL/TLS certificates managed centrally or per application?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1472" data-end="1524"&gt;
&lt;P data-start="1474" data-end="1524"&gt;Will SSL offloading or SSL inspection be required?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1525" data-end="1579"&gt;
&lt;P data-start="1527" data-end="1579"&gt;Expected number of protected domains and subdomains?&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3 data-start="1581" data-end="1613"&gt;4. &lt;STRONG data-start="1588" data-end="1613"&gt;Security Requirements&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL data-start="1614" data-end="1978"&gt;
&lt;LI data-start="1614" data-end="1723"&gt;
&lt;P data-start="1616" data-end="1723"&gt;What attack vectors are of most concern (OWASP Top 10, Bot protection, API abuse, DDoS, zero-day exploits)?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1724" data-end="1781"&gt;
&lt;P data-start="1726" data-end="1781"&gt;Is virtual patching required for known vulnerabilities?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1782" data-end="1842"&gt;
&lt;P data-start="1784" data-end="1842"&gt;Is bot management (good vs. bad bot distinction) required?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1843" data-end="1896"&gt;
&lt;P data-start="1845" data-end="1896"&gt;Should the WAF integrate with an existing SIEM/SOC?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1897" data-end="1978"&gt;
&lt;P data-start="1899" data-end="1978"&gt;Any requirements for custom rules (Geo-blocking, IP reputation, rate limiting)?&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3 data-start="1980" data-end="2015"&gt;5. &lt;STRONG data-start="1987" data-end="2015"&gt;Integration &amp;amp; Operations&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL data-start="2016" data-end="2373"&gt;
&lt;LI data-start="2016" data-end="2094"&gt;
&lt;P data-start="2018" data-end="2094"&gt;How will policies be managed (centrally via Infinity Portal / SmartConsole)?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2095" data-end="2174"&gt;
&lt;P data-start="2097" data-end="2174"&gt;Are there existing automation/orchestration tools (Terraform, Ansible, etc.)?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2175" data-end="2234"&gt;
&lt;P data-start="2177" data-end="2234"&gt;How should logs be exported (Syslog, Log exporter, SIEM)?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2235" data-end="2307"&gt;
&lt;P data-start="2237" data-end="2307"&gt;Is there a requirement for high availability or multi-site redundancy?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2308" data-end="2373"&gt;
&lt;P data-start="2310" data-end="2373"&gt;Do you need reporting dashboards for compliance and management?&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3 data-start="2375" data-end="2406"&gt;6. &lt;STRONG data-start="2382" data-end="2406"&gt;Performance &amp;amp; Sizing&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL data-start="2407" data-end="2640"&gt;
&lt;LI data-start="2407" data-end="2470"&gt;
&lt;P data-start="2409" data-end="2470"&gt;Peak RPS (requests per second) and total connections per app?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2471" data-end="2537"&gt;
&lt;P data-start="2473" data-end="2537"&gt;SSL/TLS offload requirements (certificate count, cipher suites)?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2538" data-end="2583"&gt;
&lt;P data-start="2540" data-end="2583"&gt;Latency tolerance (ms overhead acceptable)?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2584" data-end="2640"&gt;
&lt;P data-start="2586" data-end="2640"&gt;Do you require load testing before production rollout?&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3 data-start="2642" data-end="2672"&gt;7. &lt;STRONG data-start="2649" data-end="2672"&gt;Support &amp;amp; Ownership&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL data-start="2673" data-end="2842"&gt;
&lt;LI data-start="2673" data-end="2740"&gt;
&lt;P data-start="2675" data-end="2740"&gt;Who will manage WAF policies (Security team, DevOps, App owners)?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2741" data-end="2792"&gt;
&lt;P data-start="2743" data-end="2792"&gt;Is 24/7 support required, or business hours only?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2793" data-end="2842"&gt;
&lt;P data-start="2795" data-end="2842"&gt;What is the expected SLA for incident response?&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 18 Aug 2025 17:01:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/Scoping-Questionnaire-CloudGuard-WAF/m-p/255357#M339</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-18T17:01:41Z</dc:date>
    </item>
  </channel>
</rss>

