Authentication Enforcement | Check Point WAF

Overview

CloudGuard WAF’s Authentication Enforcement ensures that only authorized requests can access your protected web application. It validates incoming requests against the configured authentication type and can detect/block unauthenticated or improperly authenticated traffic.

How to set up Authentication Enforcement

Configuration Options

Unauthenticated Endpoints

By default, this protection applies to the entire asset.

Response Code for Unauthorized Access

The default response status code is 403 when a request is blocked, which might cause unexpected behavior, the following section explains how to configure 401 response code to align with authentication best practices.

To return a 401 Unauthorized response for blocked requests follow the steps below:

  1. create a dedicated Web User Response, with the following configurations:
  1. Assign the Web User Response to the practice.

  2. Enforce Policy.