The latest insights from the load balancing experts | Loadbalancer.org
  • Support
  • Blog
  • +1 833 274 2566
  • Solutions
  • Services
  • Products
  • Resources
  • Get Started
  • Support
  • Blog
Schedule your demo
  • Solutions
  • Services
  • Products
  • Resources
  • Get Started
  • Support
  • Blog

The latest insights from the load balancing experts | Loadbalancer.org

  • Latest posts
  • By topic
    • How Tos
    • Events
    • Guest Blogs
    • Top Ten Blogs
    • HA Proxy
  • By sector
    • Healthcare
    • Storage
    • Security
    • Print
    • Microsoft
  • How-To's
  • HAProxy
  • High Availability
  • Just for Fun
  • Security
  • Events
  • News
  • Linux
  • Top 10 Blogs
  • Amazon AWS
  • Reviews and Comparisons
  • Healthcare
  • SSL
  • Web Application Firewall (WAF)
  • Case Studies
  • Microsoft Azure
  • Disaster Recovery
  • Direct Server Return (DSR)
  • Global Server Load Balancing (GSLB)
  • Microsoft
  • Microsoft Exchange
  • Print
  • Denial of Service
  • Microsoft Remote Desktop Services
  • Object Storage
  • Web Filters / Proxy
  • Broadcast Media
  • X-Forwarded-For Header (XFF)
  • Guest Blogs
  • VMware
  • Google Cloud Platform (GCP)
  • Nutanix
See more tags

Loadbalancer.org partner with Sucuri for cloud based WAF & DDOS protection

3 September 2015 / 3 min read / News

During the last year at Loadbalancer.org we have spent a lot of time and effort researching WAF (Web Application Firewall) solutions.

The integrated WAF in version 8 of the Loadbalancer.org appliance has been designed for fast, low latency PCI compliance for our customers. We also have several customers clustering commercial solutions (such as Imperva) behind our load balancer giving a much better WAF feature set + great performance and health monitoring.

During the development process for our own integrated WAF (Web Application Firewall) solution aka. mod security, we have been doing a lot of load testing and stress testing. It is shockingly easy to accidentally create a Denial of Service attack on your own application by incorrectly configuring a WAF i.e. having too many rules and auditing mode turned on. Or writing rules that block valid traffic by mistake.

At Loadbalancer.org our support team are very happy to help our customers with custom rules and security policies.

However our recommendation is that you use a company that is 100% focused on this area before you get yourself in deep trouble :-).

So who do Loadbalancer.org recommend for a local cluster WAF solution?

Well strangely enough, at the lower end of the market we would recommend putting a couple of Barracuda WAFs behind our load balancer in a cluster. These are great for creating a low latency, high performance WAF cluster in front of your application. We would caution however that this is if you know what you are doing!

The Barracuda web interface is basically just a skin on top of the basic mod security functionality.

We would also recommend that you setup the Barracuda WAFs in one-arm mode.

If you need a more advanced solution, then you will definitely want to be looking at either Imperva or F5 WAFs.

Why can't I use a cloud based WAF solution?

Good question, and its one we get asked a lot of times.

Yes you can use a cloud based WAF!

In fact for the vast majority of our customers it is actually our default recommendation.

For the vast majority of applications a combination of cloud CDN and WAF can easily give you a responsive low latency solution (realistically low enough for most customers anyway).

So who do Loadbalancer.org recommend for a cloud based WAF?

Sucuri.

Its fast , its cheap, and its run by people who really give a damn. We like it so much that we moved the Loadbalancer.org web site is behind the Sucuri WAF.

Admittedly one of the reasons was that we changed the main web site to be based on WordPress and were petrified that it would get hacked :-). Obviously we have secured it ourselves (using the usual tricks like an extra htaccess based password on the admin page) . However it is nice and easy in the Sucuri interface to add two factor authentication to the WordPress administration section (so we have done that as well for double the security.)

BTW: CloudFlare deserves a second place mention for our recommended cloud based WAF.

Now for some very un-scientific test data:

Chrome network load data for www.loadbalancer.org/company  (Direct from our EC2 instance of wordpress): Approx 2.4 seconds load time....
lbserverdirect

Chrome network load data for loadbalancer.org/company through the Sucuri network WAF & CDN: Approx 1.8 seconds load time..... sucuri It doesn't prove anything really, but adding the Sucuri WAF certainly doesn't add any latency to our web server.....  :-).

Found in

News, Security, Web Application Firewall (WAF)

About the author

Andrew Zak-profile-image
Andrew Zak

Andrew is a Portsmouth University graduate in Computer Science with a passion for technology. Originally from Brussels, Belgium Andrew has lived in France, Switzerland, the Netherlands, the United Kingdom, and the United States. He maintains a proficiency in Spanish and an understanding of Portuguese. In his free time, Andrew enjoys travelling, working on his side projects, cycling and skiing.

Read More

Related posts

Top 10 Blogs
Top 10 Blogs
4 Jan 2021
11 technology lessons to take into 2021 Tom Hopkins
Despite everything, 2020 was actually a pretty good year for tech - find out which trends are sticking around in 2021.

5 min read

Read more
HAProxy
HAProxy
26 Aug 2020
Loadbalancer.org releases Open Source SNMP MIB and Agent for HAProxy Peter Statham
We’re always keen to give back to the community that writes such great software – our new SNMP agents and MIBs for HAProxy make monitoring your Virtual Services and Real Servers a breeze.

7 min read

Read more
Global Server Load Balancing (GSLB)
Global Server Load Balancing (GSLB)
12 Sep 2015
Cloud based GSLB made simple with concierge service from Loadbalancer.org Theo Garvey
Anyone who has been watching Loadbalancer.org over the last few years will have noticed the things that we don't like :-). We've made it pretty clear that we don't like load balancing firewalls and we've also been pretty reluctant to turn our load balancers into a GSLB.

2 min read

Read more

Get started

Get in touch

Start a conversation about the right solution for your business.

Get in touch

Create your quote

Transparent pricing you can see straight away.

Create your quote

Download now

Try us free for 30 days – see why our customers love us.

Download now

Schedule a virtual meeting with us

Working remotely or from home? Let’s meet on a call or online.

Let's meet

Follow Loadbalancer.org

+1 833 274 2566
  • Company
    • Solutions
    • Services
    • Load balancer
    • Why Loadbalancer.org
    • Blog
    • Professional services
    • Sitemap
  • Load balancer
    • Get a quote
    • Free trial
    • Online demo
  • Resources
    • Manuals
    • Deployment guides
    • Applications
    • White papers
    • Case studies
    • Solutions
  • Support
    • FAQ's
    • Open a ticket
    • Security news
  • Applications
    • Healthcare
    • Storage
    • Print
    • Security
    • Microsoft
The latest insights from the load balancing experts | Loadbalancer.org

The latest insights from the load balancing experts | Loadbalancer.org. All rights reserved

  • Contact Us
  • Terms & Conditions
  • Privacy Policy