Introduction to common deployment methods of WAF Web application firewall
1. Transparent proxy mode, which can be understood as a switch. The traffic is first processed by WAF and then to the firewall.
2. Reverse proxy, one-arm mode, which needs to map the traffic of external users accessing the private network server to WAF through NAT Server, and then forward it to the server after processing by WAF. The reverse one-arm mode can support VRRP protocol, and the dual-machine HA mode can be realized by deploying two H3C SecPath WAF to enable VRRP protocol.
3. Reverse proxy, dual-arm mode, WAF interface works in three-tier mode, the same method, using mapping method to map traffic to WAF, and then reverse proxy from WAF to WEB server
4. Reverse proxy, link mode traction mode deployment: this mode can be deployed by bypass, and the traffic accessing the server can be redirected to the WAF service interface through PBR without configuration mapping. Traction mode can support VRRP protocol, and dual-machine HA mode can be realized by deploying two H3C SecPath WAF to enable VRRP protocol.
5. Deployment of bypass monitoring mode, which can be deployed offline, does not affect online business, user traffic analysis or log audit, and cannot achieve protection. Close users can observe traffic scenarios.
6. Route pattern deployment: no different from ordinary router deployment. The incoming traffic from the public network will be securely processed to the WAF and then forwarded to the intranet WEB server.