edgeWAF

Web Application Firewall

Start with built-in edgeWAF protection and scale to enterprise-grade security powered by Check Point, all within the Total Uptime ADC platform.

Your applications are exposed. Your architecture does not need to get more complicated.

Web applications and APIs are prime attack targets, but adding a separate WAF often means another appliance, another policy layer, another failure domain and another vendor to manage.  For organizations that also need to keep traffic and security controls inside their own infrastructure, cloud-only WAF services can introduce the wrong dependency.

The real challenge is protecting applications without making application delivery more complex.

Why edgeWAF?

edgeWAF is Total Uptime’s self-hosted Web Application Firewall, designed to protect applications and APIs at Layer 7 while fitting directly into the application delivery architecture.

One application delivery and security platform

edgeWAF and edgeADC can operate together in the same platform, combining application security with Layer 7 load balancing, content switching, pre-authentication and traffic analytics.  That means security inspection does not have to become a separate infrastructure tier with its own appliance and operational model.

Keep application traffic under your control

The self-hosted platform runs inside infrastructure you control.  Deploy on virtual infrastructure, dedicated hardware, public cloud or private cloud without requiring application traffic to traverse Total Uptime’s cloud.  That makes edgeWAF particularly relevant where infrastructure control, data residency, internal applications or architectural independence matter.

Start with the protection you need. Expand without re-platforming.

Not every application requires the same security model.  edgeWAF Essentials provides integrated WAF protection for applications requiring core Layer 7 controls.  For higher-risk, Internet-facing or compliance-sensitive applications, enterprise WAF capabilities powered by Check Point add advanced behavioural protection, threat intelligence and automated security capabilities.

 

What does edgeWAF do?

edgeWAF sits in the application traffic path and inspects HTTP/HTTPS requests before they reach the application.  Instead of relying solely on IP addresses and ports, it can evaluate what the application request is actually trying to do.

Application-layer attack protection

Protect applications against common application attack techniques.

HTTP and application policy enforcement

Inspect requests and responses and enforce policies based on application behaviour rather than simply network connectivity.

Sensitive-data protection

Create controls designed to prevent sensitive information, including payment-card data, from unintentionally leaving protected applications.

Application-specific policies

Apply WAF profiles according to the requirements of individual applications rather than forcing every service through an identical security policy.

Real-time visibility

See application traffic and security events through the management interface so infrastructure and security teams can understand what is being blocked and why.

Advanced threat protection

For applications requiring a higher level of security, Check Point-powered WAF options add behavioural analysis, global threat intelligence, automated updates and advanced protection against emerging and zero-day threats.

WAF and application delivery in the same traffic path

Combine application security and traffic management in one platform to reduce complexity, infrastructure layers and operational overhead.

edgeWAF Diagram

Choose the level of protection that matches the application.

Not every application carries the same risk. Choose the protection level that fits each application’s exposure, security requirements and compliance needs without changing the underlying platform.

edgeWAF Essentials

edgeWAF Essentials provides core WAF protection built directly into the edgeADC
Includes
  • Basic threat protection
  • Layer-7 inspection
  • Core rule sets
  • Essential routing and load balancing integration
  • Flat costed, not based on usage/requests

Enterprise Security with Check Point

Enterprise WAF Powered by Check Point
Includes
  • Global threat intelligence
  • Automatic cloud-driven updates
  • Protection against zero-day threats
  • Enterprise compliance support
  • Advanced attack prevention

Deploy where your applications already run

Security architecture should follow the workload, not force the workload to follow the security vendor.

VMware, Hyper-V, KVM and Nutanix

Run edgeADC and edgeWAF as virtual infrastructure inside your existing environment.

AWS and Microsoft Azure

Deploy alongside cloud workloads while retaining the same application delivery approach used on-premises.

Dedicated infrastructure

Run the platform on dedicated hardware where physical deployment or isolation is required.

Hybrid environments

Use the same application delivery platform across cloud and on-premises infrastructure instead of introducing a different security architecture for every environment.

Built by application delivery engineers.

Application security is only one part of keeping an application available.  Total Uptime brings together DNS, global traffic management, load balancing, application delivery, WAF and networking expertise so that security decisions can be considered in the context of the complete request path.

24×7 technical support is available from people who understand the platform.

Customer success

Trusted by IT Teams Worldwide

Real organisations. Real resilience. Real results.

Rated by the people who use us.

Protect the application. Simplify the architecture.

If you’re reviewing your WAF because of cost, complexity, an upcoming renewal, or a changing cloud and on-premises strategy, talk directly with one of our engineers.