Re: Deployment Options
Eero Volotinen <[email protected]>
| Newsgroups | gmane.comp.apache.mod-security.user |
|---|---|
| Message-ID | <CABzZrXf-xRqcR_6j7e4yL8LOs4zGJFkghEiqr0Ny1Cgo8yimCg@mail.gmail.com> |
How about Nginx with WAF as proxy? Eero Parrish, Kyle <[email protected]> kirjoitti pe 14. jouluk. 2018 klo 17.15: > Good morning all, > > > > Seeking advice on deploying a Web Application Firewall. > > > > I’m pretty familiar with WAFs and what they will do but stuck on an ideal > deployment structure. > > > > Lets say there are 20 websites sitting behind a reverse proxy. > > My idea would be to have: > > 1. Request hits proxy > 2. Checks to see if it has been WAF’ed or not > 3. Sends to WAF > 4. If approved goes back to be proxied to correct backend > > > > Now, would it be okay to have 20 sites sent through a single WAF or should > each site be configured for its own? > > > > I am looking to use OWASP ModSecurity for the WAF ruleset but not familiar > with its scalability yet. > > > > Hoping someone else has already gone down this path and could shed some > light on it. > > > > *B. Kyle Parrish* > > > _______________________________________________ > mod-security-users mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/mod-security-users > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: > http://www.modsecurity.org/projects/commercial/rules/ > http://www.modsecurity.org/projects/commercial/support/ > _______________________________________________ mod-security-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/mod-security-users Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: http://www.modsecurity.org/projects/commercial/rules/ http://www.modsecurity.org/projects/commercial/support/