Navigation

    APPDRAG Community

    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Popular

    REMINDER

    Please be respectful of all AppDragers! Keep it really civil so that we can make the AppDrag community of builders as embracing, positive and inspiring as possible.

    SOLVED Protection with WAF

    Cloud Backend (Cloud DB, API Builder)
    3
    5
    410
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Mody Ibrahim
      Mody Ibrahim last edited by

      Hello,
      It's mentioned here:
      https://appdrag.com/docs/AppDrag_White_Paper_v1.3.pdf

      "AppDrag leverages AWS’s security infrastructure ​ (CloudFront,
      LoadBalancer, WAF, DDOS protection, VPN, IAM, security groups,
      replication on multiples regions, versioning and Cloudwatch alerts) "

      Does that mean that Cloud Backend comes bundled with WAF protection? As in, if someone spams my API endpoints, do I have protection against that? If not, is it possible for me to leverage WAF to protect my API against common attacks?

      J 1 Reply Last reply Reply Quote 0
      • J
        jbenguira @Mody Ibrahim last edited by

        Hey @mody-ibrahim
        We do have a waf but it won't be configurable/adjustable by you this is why I recommended you to configure Cloudflare (free) to get an additional protection layer that you can configure with rules

        1 Reply Last reply Reply Quote 1
        • Mody Ibrahim
          Mody Ibrahim last edited by

          @jbenguira Oh, thank you. I'm already using CloudFlare to serve my frontend and protect it from DDoS while using AppDrag's Cloud Backend for my API. Does that mean my API already has proper protection against abuse without being connected to CloudFlare's WAF? Any documentation on the subject?

          Joseph Benguira 1 Reply Last reply Reply Quote 0
          • Joseph Benguira
            Joseph Benguira @Mody Ibrahim last edited by

            @mody-ibrahim you can connect a domain to your project, and call the api through your custom domain (protected by cloudflare)

            As already said above, yes we do have a layer of WAF protection on our side on AppDrag & Cloud Backend, but it's not configurable by end users. It's intended to protect our system but won't prevent someone from using all your api quota ... You could definitely prevent that with cloudflare and specific rules for your sensible api endpoints

            1 Reply Last reply Reply Quote 1
            • Mody Ibrahim
              Mody Ibrahim last edited by

              Very useful answers. Thank you!

              1 Reply Last reply Reply Quote 1
              • First post
                Last post