<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blueprint design for inbound webtraffic in onpremise datacenter in WAF</title>
    <link>https://community.checkpoint.com/t5/WAF/Blueprint-design-for-inbound-webtraffic-in-onpremise-datacenter/m-p/130842#M49</link>
    <description>&lt;P&gt;My guess is that it would probably be similar to that in public cloud except you're using on-prem load balancers.&lt;BR /&gt;AppSec can also do IPS:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13847i7BE673894522CEC3/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 01 Oct 2021 18:23:50 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-10-01T18:23:50Z</dc:date>
    <item>
      <title>Blueprint design for inbound webtraffic in onpremise datacenter</title>
      <link>https://community.checkpoint.com/t5/WAF/Blueprint-design-for-inbound-webtraffic-in-onpremise-datacenter/m-p/130820#M48</link>
      <description>&lt;P&gt;We are looking for a design concept or best practice setups for onpremise datacenter environment where 90% of traffic is inbound https.&lt;/P&gt;&lt;P&gt;We are already using R80.40 clusters and Citrix netscalers (for loadbalancing and ssl offloading) but we also want to use the Appsec.&lt;/P&gt;&lt;P&gt;Upgrade to R81 is planned.&lt;/P&gt;&lt;P&gt;Does Checkpoint has some kind of document or blueprint in order to create the best setup for doing security on this incoming https traffic.&lt;/P&gt;&lt;P&gt;One question for example is which component can or should do IPS. The gateway or the appsec.. or both ?&lt;/P&gt;&lt;P&gt;Please let me know which thoughts about those kind of setups are the in community&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Oct 2021 12:23:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/Blueprint-design-for-inbound-webtraffic-in-onpremise-datacenter/m-p/130820#M48</guid>
      <dc:creator>Mischa_Meekes</dc:creator>
      <dc:date>2021-10-01T12:23:18Z</dc:date>
    </item>
    <item>
      <title>Re: Blueprint design for inbound webtraffic in onpremise datacenter</title>
      <link>https://community.checkpoint.com/t5/WAF/Blueprint-design-for-inbound-webtraffic-in-onpremise-datacenter/m-p/130842#M49</link>
      <description>&lt;P&gt;My guess is that it would probably be similar to that in public cloud except you're using on-prem load balancers.&lt;BR /&gt;AppSec can also do IPS:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13847i7BE673894522CEC3/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Oct 2021 18:23:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/Blueprint-design-for-inbound-webtraffic-in-onpremise-datacenter/m-p/130842#M49</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-10-01T18:23:50Z</dc:date>
    </item>
    <item>
      <title>Re: Blueprint design for inbound webtraffic in onpremise datacenter</title>
      <link>https://community.checkpoint.com/t5/WAF/Blueprint-design-for-inbound-webtraffic-in-onpremise-datacenter/m-p/130873#M50</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;if you want to use AppSec then it also has IPS capabilities specifically for WEB traffic. So it you activate it on AppSec you don't need to do double inspection and activate it on the Gateways also.&lt;/P&gt;
&lt;P&gt;you might just activate it for other protocols passing through your Gateways using the Threat Prevention policy.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Oct 2021 08:04:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/Blueprint-design-for-inbound-webtraffic-in-onpremise-datacenter/m-p/130873#M50</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2021-10-03T08:04:53Z</dc:date>
    </item>
  </channel>
</rss>

