Protect a Web Application / API | Check Point WAF

For the complete documentation index, see llms.txt. This page is also available as Markdown.

Check Point WAF provides a configuration wizard that allows you to set up everything you need for basic protection of your web application. Once you completed the wizard you can set up a Check Point WAF's AppSec Gateway or Agent to enforce security.

New Asset Wizard

Launch the configuration wizard:

Follow these configuration steps in the New Web Application / API wizard:

Step 1: Application Details

Complete the following details (which you have prepared before):

Multiple "Application URL for the reverse proxy function" to enable Load Balancing can be configured once asset has been created

For VM, SaaS, or managed Docker deployments, you must provide the internal URL (application, API, or internal load balancer). This URL should be accessible to the Reverse Proxy but not exposed externally.

Step 2: Platform and Deployment configuration

  1. Choose a deployment method:

Check Point WAF can be deployed as:

Step 3: Practices

Select the Practices that you want to enable and their Mode:

Modes:

Step 4: GenAI Protection

Use the GenAI Protection Settings to define how your application or API is secured, if you've enabled the GenAI Protection Practice in the previous step.

Step 5: Learning

Define how the Machine Learning engine should distinguish between different API or Human users and who the users are that can be trusted.

  1. Select the method by which different users will be distinguished from one another:

In the less common case, where there is more than 1 reverse proxy and/or ALB deployments before the reverse proxy with Check Point WAF:

This is explained in more details here.

Additional methods can be defined later by editing the Web Application/API asset object. These include:

  1. If you do not intend to use additional methods, you may already define trusted sources that serve as a baseline for comparison for benign behavior, and how many Users/Addresses must exhibit similar activity for it to really be considered benign by the learning model (Otherwise it is recommended to perform this step after the wizard has been completed by editing the asset and after changing the method by which users are distinguished).

Step 6: Certificate storage configuration and deployment instructions

If, during the previous step, a "New Profile" option was selected, then the "Certificates" page will also prompt a decision, relevant for all Check Point WAF's AppSec Gateways or WAF SaaS assets that will connect to this profile, regarding where the certificates for HTTPS traffic will be stored.

WAF SaaS
Appsec Gateways

For WAF SaaS deployment, you choose between a Check Point-managed certificate — Wildcard (covers all subdomains, the default) or Specific (a single domain) — or your own certificate (BYOC).

Completing the deployment requires actions after the wizard has ended, for each domain configured on the new asset:

  1. If using a Check Point-managed certificate: proving ownership of the domain see Certificates Managed by Check Point.
  2. If using your own certificate: uploading it see Bring Your Own Certificate (BYOC).
  3. Configuring the DNS record for each domain so traffic to it will be routed to WAF SaaS.

This decision is only relevant for the pre-packaged Gateway (Virtual Machine) option in AWS and Azure. In those cases, it is possible to either select a secure vault in the relevant public cloud, or local storage. This configuration can be later changed by editing the created profile via Cloud->Profiles.

If the "Existing Profile" option was selected, then it will not be possible to choose a different configuration from what is already set in this profile.

Exact setup instructions for certificates will be available in the profile page.

For Check Point WAF on AWS or Azure, there are two methods for storing certificates and private keys. For all other deployments, only the first is available:

Step 7: Reporting

During the Web Application onboarding it is possible to configure a new Report Trigger to send a summary report, based on your preferences to a list of email addresses or use an existing, pre-configured Report Trigger.

Step 7: Summary

Review the configuration summary and choose how you would like to proceed.

By keeping the default selections and clicking Done, you can Publish & Enforce your settings and proceed to the Profile page, which includes instructions for deployment of a Check Point WAF's AppSec Gateway, WAF SaaS or Agent.

You can also choose Advanced Settings to explore additional features and later proceed with enforcement point deployment.

Deploy Enforcement Point - Gateway or Agent

You are minutes away from protecting your Web Application. The last step is to deploy an Enforcement Point. See instructions here:

Deploy Enforcement Point