Airlock Web Application Firewall
Within the secure access hub, Airlock WAF acts as a central reverse proxy for all HTTPS connections and protects against web attacks.
Airlock WAF works in conjunction with Airlock IAM to ensure secure session management while serving as a policy enforcement point for authentication and authorisation decisions.
A web portal is a very exposed thing and must be specially secured in every case. It was therefore clear to us that we wanted to protect the web applications from unauthorized access in the best possible way with upstream security functions in a web application firewall (WAF).
Martin Burri, IT Security Officer Visana
- Filtering (Attack blocking)
- Fraud detection
- Threat Intelligence
- Rapid deployment – DevSecOps
- Reporting & monitoring
- SIEM integration
- Virtual patching
- Load balancing
- Learning Mode for easier administration
- MS applications
Airlock can be quickly and easily deployed in the Google Cloud. Existing Airlock licenses can be used for operation in the Google Cloud. The operation follows the BYOL model (Bring your own Licence).
Airlock Gateway 7.4 and Airlock Microgateway 1.0
What is the Airlock Gateway?
The Airlock Secure Access Hub contains the three products Airlock WAF, Airlock API and Airlock IAM. However, when it comes to downloading, deploying or documenting the Secure Access Hub, there are only two technical components: The Airlock Gateway and Airlock IAM. Hence, we are using the term Airlock Gateway from now on when referring to the technical component which provides the functional building blocks for Airlock WAF and the content filtering functionality of Airlock API. This mainly affects technical documentation, architecture blueprints or release announcements such as this one.
The Airlock Gateway has always been available as an appliance. With the launch of the Airlock Microgateway, it is now also available as a container.
Filtering of application-based attacks
Airlock WAF analyses traffic moving between users and services. Attempted attacks on applications are blocked before they can reach the in-house systems.
Airlock WAF provides comprehensive protection against the OWASP Top 10 vulnerabilities and enables centralised management of security policies. Thanks to these innovative security functions, you can always stay ahead of attackers.
Policy enforcement point
Working in conjunction with Airlock IAM, Airlock WAF serves as a policy enforcement point for security guidelines, allowing only filtered, authenticated and authorised access.
This combination of access management and content filtering guarantees security, with no compromises.
Thanks to built-in dynamic reporting, decision makers have an overview of attempted attacks at all times. Operational problems such as performance bottlenecks or back-end problems are also displayed. Interactive drill-down from the dashboards, along with the display of the log lines causing the issue, facilitate the in-depth analysis of every attempted attack.
Airlock Threat Intelligence
Airlock WAF seamlessly integrates Webroot's Threat Intelligence Service. Based on the categories and trust levels provided, this automatically blocks dangerous clients and further increases application protection against misuse. Webroot BrightCloud® Threat Intelligence Services is a proactive, automated security solution that provides effective, real-time policy enforcement against the latest threats.
Reverse proxy functionality and high availability
Airlock WAF is a reverse proxy that makes it possible to virtualise in-house services and applications for external access. The integrated load balancer also ensures the high availability of applications and services. Even complex issues such as the configuration of TLS security and certificate management can be dealt with upstream on the central proxy.
Thanks to integrated Let’s Encrypt support, certificate renewals can even be completely automated.
Airlock WAF provides a host of interfaces with peripheral systems such as SIEM systems, virus scanners, fraud-prevention systems and HSMs. Thanks to its integrated threat intelligence feed, Airlock WAF reacts immediately to real-time threat situations on the Internet, protecting systems from new and potentially harmful hazards. Additional components can be integrated via the high-availability capable ICAP interface.
Airlock cloud image
Microgateway as a container