Setup Behavior Upon Failure | Check Point WAF

CloudGuard WAF Fail-Open Mechanism

CloudGuard WAF implements a Fail-Open mechanism designed to allow no interruption to traffic in case of load or errors. The mechanism is enabled by default and can be configured separately for each agent profile through the profile page.

Setup

This configuration is available on the Agents' Profile level and will apply to all agents using this profile's authentication token for initial registration.

To configure the behavior upon failure, navigate to Policy->Profiles->[select your profile]. See the Behavior Upon Failure section:

How does it work?

Traffic based-Fail-Open

Agent CPU based Fail-Open

In addition to the above traffic based mechanism, the system also monitors the Agent CPU level. The CPU utilization is sampled every 5 seconds. If 6 consecutive samples (30 seconds) were above 85%, we enter fail-open mode until we identify 6 consecutive samples below 60%.

Critical Errors

In case of any internal error in the attachment or agent during HTTP inspection, traffic will be allowed by default.

Notification logs about critical alerts will be shown in a Notifications logs view.

Previous Setup Notification Triggers
Next Setup Agent Upgrade Schedule

Last updated 1 year ago.