Grafik Airlock WAF

Airlock WAF

The Web Application Firewall for the highest demands on IT security

Airlock Web Application Firewall

Within the secure access hub, Airlock WAF acts as a central reverse proxy for all HTTPS connections and protects against web attacks.

Airlock WAF works in conjunction with Airlock IAM to ensure secure session management while serving as a policy enforcement point for authentication and authorisation decisions.

A web portal is a very exposed thing and must be specially secured in every case. It was therefore clear to us that we wanted to protect the web applications from unauthorized access in the best possible way with upstream security functions in a web application firewall (WAF).

Martin Burri, IT Security Officer Visana


Case Study


Airlock WAF

  • Filtering (Attack blocking)
  • Fraud detection
  • Threat Intelligence 
  • Rapid deployment – DevSecOps
  • Reporting & monitoring
  • SIEM integration
  • Virtual patching
  • Load balancing
  • Learning Mode for easier administration
  • MS applications

Airlock Microgateway 1.0

With the advent of microservice architectures and DevOps practices, central security gateways concentrating many tasks for all services on a single system have increasingly been challenged. The various stakeholders may have differing requirements, timelines and policies for the single system they share.

Airlock Microgateway it is now available as a container.


Airlock can be quickly and easily deployed in the Google Cloud. Existing Airlock licenses can be used for operation in the Google Cloud. The operation follows the BYOL model (Bring your own Licence).


Just try it.

Airlock can be operated in the Azure Cloud as well. In the Azure Cloud the operation is also carried out in the BYOL model (Bring your own Licence).

Just try it.

Airlock Gateway 7.5

IPv6 and multi-user administration - these are the main topics of Airlock Gateway 7.5. IPv6 is now supported not only externally but also internally, paving the way for seamless integration into IPv6 environments. For large installations with several administrators, the new configuration merge feature makes life much easier. As long as administrators are working on independent parts of the configuration, simultaneous changes can be integrated automatically. Moreover, cluster support via REST has been enhanced and there is now an easy way to rewrite JSON objects.

Airlock Gateway 7.5 was released on 4th of December 2020.

Read more

Filtering of application-based attacks

Airlock WAF analyses traffic moving between users and services. Attempted attacks on applications are blocked before they can reach the in-house systems. 

Airlock WAF provides comprehensive protection against the OWASP Top 10 vulnerabilities and enables centralised management of security policies. Thanks to these innovative security functions, you can always stay ahead of attackers.

Learn more about filtering

Policy enforcement point

Working in conjunction with Airlock IAM, Airlock WAF serves as a policy enforcement point for security guidelines, allowing only filtered, authenticated and authorised access.

This combination of access management and content filtering guarantees security, with no compromises.

Security dashboards

Thanks to built-in dynamic reporting, decision makers have an overview of attempted attacks at all times. Operational problems such as performance bottlenecks or back-end problems are also displayed. Interactive drill-down from the dashboards, along with the display of the log lines causing the issue, facilitate the in-depth analysis of every attempted attack.

Learn more about reporting and SIEM integration

Airlock Threat Intelligence

Airlock WAF seamlessly integrates Webroot's Threat Intelligence Service. Based on the categories and trust levels provided, this automatically blocks dangerous clients and further increases application protection against misuse. Webroot BrightCloud® Threat Intelligence Services is a proactive, automated security solution that provides effective, real-time policy enforcement against the latest threats.


Reverse proxy functionality and high availability

Airlock WAF is a reverse proxy that makes it possible to virtualise in-house services and applications for external access. The integrated load balancer also ensures the high availability of applications and services. Even complex issues such as the configuration of TLS security and certificate management can be dealt with upstream on the central proxy.

Thanks to integrated Let’s Encrypt support, certificate renewals can even be completely automated.

Learn more about high availability

Central hub

Airlock WAF provides a host of interfaces with peripheral systems such as SIEM systems, virus scanners, fraud-prevention systems and HSMs. Thanks to its integrated threat intelligence feed, Airlock WAF reacts immediately to real-time threat situations on the Internet, protecting systems from new and potentially harmful hazards. Additional components can be integrated via the high-availability capable ICAP interface.


With its comprehensive REST API, Airlock WAF is easy to integrate into modern DevOps pipelines and can be supplied as hardware, virtual appliance or cloud image.

Learn more about DevSecOps


Virtual appliance

Hardware appliance

Airlock cloud image

Microgateway as a container

Ready for excellent IT security?

Contact us now.
Ergon Informatik AG+41 44 268 87 00

Information for you

-Our whitepaper-

IT-security solutions

Digitalisation is presenting businesses with new challenges which go far beyond information technology. This primarily relates to an aspect which is becoming increasingly important: IT security.

Read our whitepaper to find out how IT-Security will become the pioneer of degitalization.

Request free of charge

Accelerate digitisation

To stay technically viable in this digital transformation, you must increasingly switch to hybrid cloud environments. This requires new security approaches as well as coordinated identity and access management.

Find out more in our whitepaper in collaboration with Deloitte, eperi and SHE.

Request free of charge

OWASP Top 10 for API Security

OWASP has created a new Top10 list for API Security. The top 10 listed reflect a broad consensus on what the most important API security issues are at the moment.

In our whitepaper you will learn how our Airlock API addresses the OWASP Top 10.

Request free of charge