Grafik Airlock WAF

Airlock Gateway

Complete protection for web applications and APIs

Web Application + API Protection (WAAP)

Airlock Gateway protects mission-critical, web-based applications and APIs from attacks and undesired visitors. As a central security instance, it examines every HTTP(S) request for attacks and thus blocks any attempt at data theft and manipulation. In combination with Airlock Microgateway and Airlock IAM, this creates a unique architecture for stronger application security.

Airlock Gateway is both a web application firewall (WAF) and an API security gateway. It also protects against undesired bots and DoS attacks. This product category is also called Web Application and API Protection (WAAP).

 

WAAP Capabilities

A web portal is a very exposed thing and must be specially secured in every case. It was therefore clear to us that we wanted to protect the web applications from unauthorized access in the best possible way with upstream security functions in a web application firewall (WAF).

Martin Burri, IT Security Officer Visana

 

Case Study

 

Airlock Gateway

Highlights

Airlock Microgateway

With the advent of microservice architectures and DevOps practices, central security gateways concentrating many tasks for all services on a single system have increasingly been challenged. The various stakeholders may have differing requirements, timelines and policies for the single system they share.

Airlock Microgateway is also available as a community edition.

 

Airlock Gateway can be quickly and easily deployed in the Google Cloud. Existing Airlock licenses can be used for operation in the Google Cloud. The operation follows the BYOL model (Bring your own Licence).

 

Just try it.

Airlock Gateway can be operated in the Azure Cloud as well. In the Azure Cloud the operation is also carried out in the BYOL model (Bring your own Licence).

Just try it.

Airlock Gateway 8.0

Airlock Gateway 8.0 is based on a new Linux distribution and contains various functional improvements. These include a substantial simplification in the configuration of the Airlock Anomaly Shield. In order to expand the possibilities of automation, the REST interface has been significantly expanded and a Python library has been added.

Read more

Filters of a Web Application Firewall

Airlock Gateway analyses traffic moving between users and services. Attempted attacks on applications are blocked before they can reach the in-house systems. 

Airlock Gateway provides comprehensive protection against the OWASP Top 10 vulnerabilities and enables centralised management of security policies. Thanks to these innovative security functions, you can always stay ahead of attackers.

Learn more about filtering

API access control

One of the main reasons for using API gateways is to ensure access control to APIs. Airlock Gateway validates access tokens and permits role-based access authorisation for API end points. Airlock Gateway works in conjunction with Airlock IAM to support these protocols when protecting access to APIs:

  • OAuth 2.0
  • OpenID Connect 1.0
  • SAML 2.0

Security dashboards

Thanks to built-in dynamic reporting, decision makers have an overview of attempted attacks at all times. Operational problems such as performance bottlenecks or back-end problems are also displayed. Interactive drill-down from the dashboards, along with the display of the log lines causing the issue, facilitate the in-depth analysis of every attempted attack.

Learn more about reporting and SIEM integration

Airlock Threat Intelligence

Airlock Gateway seamlessly integrates Webroot's Threat Intelligence Service. Based on the categories and trust levels provided, this automatically blocks dangerous clients and further increases application protection against misuse. Webroot BrightCloud® Threat Intelligence Services is a proactive, automated security solution that provides effective, real-time policy enforcement against the latest threats.

 

Central hub

Airlock Gateway provides a host of interfaces with peripheral systems such as SIEM systems, virus scanners, fraud-prevention systems and HSMs. Thanks to its integrated threat intelligence feed, Airlock Gateway reacts immediately to real-time threat situations on the Internet, protecting systems from new and potentially harmful hazards. Additional components can be integrated via the high-availability capable ICAP interface.

DevSecOps

With its comprehensive REST API, Airlock Gateway is easy to integrate into modern DevOps pipelines and can be supplied as virtual appliance or cloud image.

Learn more about DevSecOps

Deployment

Virtual appliance

Airlock cloud image

Airlock Microgateway as a container

Our whitepapers

Zero Trust is a journey

The digital transformation of the world continues to progress, and it is profoundly affecting private life and job profiles. Lern more about the effects of ongoing digitization and how it affects modern information technology

Request Whitepaper Zero Trust

Airlock 2FA

The two-factor authentication (2FA, MFA or SCA for short) in the area of IT security offers double the security. In combination with efficient customer identity & access management (cIAM), numerous processes are significantly simplified. Find out more about strong authentication and the possibilities that Airlock offers in our whitepaper.

Request Whitepaper Airlock 2FA

From spoilsport to the pioneer of digitisation

Digitisation is presenting businesses with new challenges which go far beyond information technology. This primarily relates to an aspect which is becoming increasingly important: IT security. Learn how IT security is accelerating digitization.


Request Whitepaper IT Security

Accelerate digitisation

In order to stay technically viable in this digital transformation, companies must increasingly switch to hybrid cloud environments. This requires new security approaches as well as a mature customer identity and access management system. Learn more about this topic in our whitepaper in cooperation with our partners Deloitte, eperi und SHE.

Request Whitepaper Accelerate digitisation

Ready for excellent IT security?

Contact us now.
Ergon Informatik AG+41 44 268 87 00

Information for you

-Our whitepapers-

Visit us at it-sa!

From 8 to 10 October you can visit us at the it-sa, the largest IT security event in Europe. Learn the latest news about application security, API security, access management and cloud security. In our congress on 9 October you can learn in many further lectures how you should turn your IT security from a spoilsport to an accelerator of your digitization projects.

Register now and get a free ticket

Study Application and API Security 2022

In a recent study in cooperation with CIO, CSO and COMPUTERWOCHE, Ergon Airlock looked at application and API security in the container environment.

Request study

Zero Trust is a journey

The digital transformation of the world continues to progress, and it is profoundly affecting private life and job profiles in a manner that was hard to imagine just a few years ago.

This whitepaper covers the effects of continuous digitization and its implications.

Request free of charge

Toward DevSecOps

In this whitepaper, you will learn the most important insights into how you can successfully and efficiently implement DevSecOps, which security components are required for this, and what benefits a microgateway architecture brings.

Request free of charge

Airlock 2FA - Strong Authentication. Easy.

The two-factor authentication in the area of IT security offers double the security.

Find out more about strong authentication and the possibilities that Airlock offers in our whitepaper.

Request free of charge

Further whitepapers

We provide whitepapers on these and other topics free of charge:

  • successful IAM projects
  • Compliance
  • Data protection (GDPR)
  • Introduction of PSD2
  • PCI DSS requirements
Request free of charge