- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- CloudGuard - WAF
- :
- Scoping Questionnaire - CloudGuard WAF
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Scoping Questionnaire - CloudGuard WAF
Hi all,
Does anybody have a scoping questionnaire for ClodGuard WAF Agent (VMware) to understand the customer requirement?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For CloudGuard WAF deployments, we have a section in the documentation that covers the information we would need to deploy.
Not sure if that's exactly what you're looking for, but perhaps it will help: https://waf-doc.inext.checkpoint.com/getting-started/prepare-key-information
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Apart from what @PhoneBoy had sent, here is something additional that can also help.
Andy
✅ CloudGuard WAF Agent (VMware) – Scoping Questionnaire
1. Customer Environment
-
What is the current VMware version and edition (vSphere, ESXi, vCenter)?
-
How many ESXi hosts and clusters are in scope for WAF deployment?
-
Are there any existing Check Point products in use (e.g., CloudGuard Network, Harmony Endpoint)?
-
What is the expected traffic volume (peak and average throughput)?
-
Are applications hosted in a single datacenter or multiple datacenters?
2. Applications in Scope
-
Which web applications need to be protected?
-
What are the application platforms (IIS, Apache, Nginx, Tomcat, etc.)?
-
Are applications containerized, VM-based, or hybrid?
-
Do applications use APIs (REST, SOAP, GraphQL, JSON)?
-
Are applications internal, external (internet-facing), or both?
-
Are there compliance requirements (PCI DSS, HIPAA, GDPR, etc.)?
3. Networking & Traffic Flow
-
How is traffic currently routed to the applications (Load Balancer, Reverse Proxy, Direct)?
-
Where will the WAF Agent be deployed in the network path (inline, TAP, sidecar)?
-
Are SSL/TLS certificates managed centrally or per application?
-
Will SSL offloading or SSL inspection be required?
-
Expected number of protected domains and subdomains?
4. Security Requirements
-
What attack vectors are of most concern (OWASP Top 10, Bot protection, API abuse, DDoS, zero-day exploits)?
-
Is virtual patching required for known vulnerabilities?
-
Is bot management (good vs. bad bot distinction) required?
-
Should the WAF integrate with an existing SIEM/SOC?
-
Any requirements for custom rules (Geo-blocking, IP reputation, rate limiting)?
5. Integration & Operations
-
How will policies be managed (centrally via Infinity Portal / SmartConsole)?
-
Are there existing automation/orchestration tools (Terraform, Ansible, etc.)?
-
How should logs be exported (Syslog, Log exporter, SIEM)?
-
Is there a requirement for high availability or multi-site redundancy?
-
Do you need reporting dashboards for compliance and management?
6. Performance & Sizing
-
Peak RPS (requests per second) and total connections per app?
-
SSL/TLS offload requirements (certificate count, cipher suites)?
-
Latency tolerance (ms overhead acceptable)?
-
Do you require load testing before production rollout?
7. Support & Ownership
-
Who will manage WAF policies (Security team, DevOps, App owners)?
-
Is 24/7 support required, or business hours only?
-
What is the expected SLA for incident response?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For CloudGuard WAF deployments, we have a section in the documentation that covers the information we would need to deploy.
Not sure if that's exactly what you're looking for, but perhaps it will help: https://waf-doc.inext.checkpoint.com/getting-started/prepare-key-information
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Apart from what @PhoneBoy had sent, here is something additional that can also help.
Andy
✅ CloudGuard WAF Agent (VMware) – Scoping Questionnaire
1. Customer Environment
-
What is the current VMware version and edition (vSphere, ESXi, vCenter)?
-
How many ESXi hosts and clusters are in scope for WAF deployment?
-
Are there any existing Check Point products in use (e.g., CloudGuard Network, Harmony Endpoint)?
-
What is the expected traffic volume (peak and average throughput)?
-
Are applications hosted in a single datacenter or multiple datacenters?
2. Applications in Scope
-
Which web applications need to be protected?
-
What are the application platforms (IIS, Apache, Nginx, Tomcat, etc.)?
-
Are applications containerized, VM-based, or hybrid?
-
Do applications use APIs (REST, SOAP, GraphQL, JSON)?
-
Are applications internal, external (internet-facing), or both?
-
Are there compliance requirements (PCI DSS, HIPAA, GDPR, etc.)?
3. Networking & Traffic Flow
-
How is traffic currently routed to the applications (Load Balancer, Reverse Proxy, Direct)?
-
Where will the WAF Agent be deployed in the network path (inline, TAP, sidecar)?
-
Are SSL/TLS certificates managed centrally or per application?
-
Will SSL offloading or SSL inspection be required?
-
Expected number of protected domains and subdomains?
4. Security Requirements
-
What attack vectors are of most concern (OWASP Top 10, Bot protection, API abuse, DDoS, zero-day exploits)?
-
Is virtual patching required for known vulnerabilities?
-
Is bot management (good vs. bad bot distinction) required?
-
Should the WAF integrate with an existing SIEM/SOC?
-
Any requirements for custom rules (Geo-blocking, IP reputation, rate limiting)?
5. Integration & Operations
-
How will policies be managed (centrally via Infinity Portal / SmartConsole)?
-
Are there existing automation/orchestration tools (Terraform, Ansible, etc.)?
-
How should logs be exported (Syslog, Log exporter, SIEM)?
-
Is there a requirement for high availability or multi-site redundancy?
-
Do you need reporting dashboards for compliance and management?
6. Performance & Sizing
-
Peak RPS (requests per second) and total connections per app?
-
SSL/TLS offload requirements (certificate count, cipher suites)?
-
Latency tolerance (ms overhead acceptable)?
-
Do you require load testing before production rollout?
7. Support & Ownership
-
Who will manage WAF policies (Security team, DevOps, App owners)?
-
Is 24/7 support required, or business hours only?
-
What is the expected SLA for incident response?
