Cloud Defender or a traditional WAF
A Web Application Firewall (WAF) can be installed in house, as an appliance or software, or used as a managed service. What changes for your sites and APIs.
In short
There is no right choice for everyone: it depends on where the applications are and who can look after them every day.
Cloud Defender
- You protect sites and APIs exposed to the internet and nobody in the company has time to run a WAF.
- You want DDoS protection and malicious IP blocking without installing hardware.
- You want to see blocked attacks in Cyber Console, next to the other services.
In-house WAF
- You need to protect internal applications that are not reachable from the internet.
- Contractual or regulatory constraints prevent traffic from passing through an external service.
- You need very specific rules and have a team that writes and maintains them.
Point by point
| Criterion | Cloud Defender | In-house WAF |
|---|---|---|
| Activation | Cloud DefenderA DNS record pointing to secure.aegister.com, with no code changes | In-house WAFInstallation, configuration and placement in the network |
| Maintenance | Cloud DefenderUpdates and rules are on us | In-house WAFUpdates, patches and capacity are on you |
| Rules against SQL injection and XSS | Cloud DefenderTuned by us to your traffic | In-house WAFConfigured and maintained in house |
| Malicious IP addresses | Cloud DefenderBlocked with our threat intelligence, list updated automatically | In-house WAFIf the product has a feed and the licence includes it |
| Volumetric DDoS attacks | Cloud DefenderHandled at the edge, before your line | In-house WAFA device in house cannot stop an attack that saturates the connection |
| Direct access to the server | Cloud DefenderThe server accepts only traffic that comes through Cloud Defender | In-house WAFDepends on how the network is configured |
| TLS certificates | Cloud DefenderHandled at the edge | In-house WAFHandled by you |
| Internal applications | Cloud DefenderNot covered: Cloud Defender protects what is exposed to the internet | In-house WAFCovered, if the WAF sits in the internal network |
| Visibility | Cloud DefenderIn Cyber Console: threats blocked, attacking IPs, origins and the layer that blocked | In-house WAFIn the WAF's console |
Getting started with Cloud Defender
-
1
Domains
Tell us which sites and APIs to protect.
-
2
DNS
The DNS record points to secure.aegister.com: requests pass through our edge.
-
3
Server
Your server accepts only traffic that comes from Cloud Defender.
-
4
Tuning
In the first weeks we tune the rules to your real traffic.
Frequently asked questions
No. A DNS record is enough: the applications stay as they are.
A few minutes for the DNS record. In the first weeks we tune the rules to your traffic.
Yes: to inspect HTTPS requests, Cloud Defender handles TLS at the edge and forwards only allowed traffic to your server.
No: it protects sites and APIs reachable from the internet. Internal applications need protection inside your network.
Other comparisons
Threat Blocker or the firewall's threat intelligence
Threat Blocker and the threat intelligence built into the firewall compared: what they block, compatibility, multiple sites, visibility and when you need both.
Full comparisonVirtual CISO or in-house CISO
Virtual CISO and in-house CISO compared: cost, presence, skills, tools and continuity. When one makes more sense than the other.
Full comparisonNot sure yet which fits you?
The Cyber Check-up returns your company's cyber profile and the priorities to start from.