## Deploying Two Docker Images

In this option, you will deploy two docker images:

- NGINX/Kong/Envoy - managed locally by you
- CloudGuard WAF Agent - centrally managed via WebUI or API

The benefit of this mode is that you can upgrade each docker separately.

### Step 1: Pull Agent Container Image

As part of your CI, use the [checkpoint/infinity-next-nano-agent](https://hub.docker.com/r/checkpoint/infinity-next-nano-agent) registry to pull the Nano-Agent image.

### Step 2: Obtain the Registration Token

Make sure you obtain the <token> from the [Enforcement **Profile**](https://waf-doc.inext.checkpoint.com/getting-started/deploy-enforcement-point) page, **Authentication** section. you will need it during agent deployment.

### Step 3: Run the Agent

Run the agent with this command:

```bash
docker run -d --name=agent-container --ipc=host -v=<path to persistent location for agent config>:/etc/cp/conf -v=<path to persistent location for agent data files>:/etc/cp/data -v=<path to persistent location for agent debugs and logs>:/var/log/nano_agent –e https_proxy=<user:password@Proxy address:port> -it <agent-image> /cp-nano-agent --token <token>
```

`–e https_proxy` parameter is optional and used only in case the outbound traffic reaches the internet through a proxy server.

### Step 4: Replace the NGINX Container with the Check Point NGINX Container

Replace the NGINX container using the following registry to pull the image for this deployment: [checkpoint/infinity-next-nginx](https://hub.docker.com/r/checkpoint/infinity-next-nginx).

As part of creating your reverse proxy for this environment, make sure that the reverse proxy is deployed with the correct downstream and upstream routing.

### Step 5: Modify the Run Command

Change your existing NGINX/Kong docker run command and add the `--ipc=host` parameter.

If you are installing a reverse proxy for the first time and have no prior knowledge of deployment methods, an example of simple deployment instructions using NGINX can be found in [the official NGINX docker hub repository](https://hub.docker.com/_/nginx).

### Step 6: Deploy the Two Containers

Deploy the two containers.

To make sure that it is running, run: `docker ps`.

### Step 7: Configure SSL Certificates (optional if the servers do not use HTTPS)

To configure SSL certificates in **NGINX** follow these guides:

- [NGINX](https://nginx.org/en/docs/http/configuring_https_servers.html)
- [NGINX PLUS](https://docs.nginx.com/nginx/admin-guide/security-controls/terminating-ssl-http/)

### Step 8: Verify Installation

Following the steps above, the agent will install and connect automatically. CloudGuard WAF web portal should display a successful connection message:

### Step 4: Replace the Kong Container with the Check Point Kong Container

Replace the NGINX container using the following registry to pull the image for this deployment:

- [Pre-packaged Kong with Nano Agent Attachment](https://hub.docker.com/r/checkpoint/infinity-next-kong-plugin)
- [Pre-packaged Kong Gateway with Nano Agent Attachment](https://hub.docker.com/r/checkpoint/infinity-next-kong-gateway-plugin)

As part of creating your reverse proxy for this environment, make sure that the reverse proxy is deployed with the correct downstream and upstream routing.

### Step 7: Configure SSL Certificates (optional if the servers do not use HTTPS)

To configure SSL certificates in **Kong** follow the guide in the following [link](https://docs.konghq.com/gateway/latest/how-kong-works/routing-traffic/#configuring-tls-for-a-route).

### Step 8: Verify Installation

Following the steps above, the agent will install and connect automatically. CloudGuard WAF web portal should display a successful connection message:

### Step 4: Replace the Envoy Container with the Check Point Envoy Container

Replace the NGINX container using the following registry to pull the image for this deployment: [checkpoint/cloudguard-waf-envoy](https://hub.docker.com/r/checkpoint/cloudguard-waf-envoy).

As part of creating your reverse proxy for this environment, make sure that the reverse proxy is deployed with the correct downstream and upstream routing.

### Step 5: Load the CloudGuard WAF Attachment in the Proxy Configuration

When installing Envoy on Docker:
As an `envoy.yaml` configuration file is not included in the Envoy container make sure to have the above configuration added yourself to that file!

In the Envoy configuration file, which is typically called `envoy.yaml` make sure to have the CloudGuard WAF attachment loaded as a filter for HTTP traffic.

The CloudGuard WAF attachment is usually located here: `/usr/lib/libenvoy_attachment.so`

### Step 8: Verify Installation

Following the steps above, the agent will install and connect automatically. CloudGuard WAF web portal should display a successful connection message:
