Skip to main content

Overview

This guide will cover the HTTP proxy service. This is designed to protect an HTTP-based Internet-facing asset against incoming threats. That includes IP Reputation, Network DDoS protection, Geo-fencing, and Application layer protection.

If you have been assigned a Threat Protection Frontend IP from our anycast range, you can protect your asset by updating the A-record in your DNS server to point to the Frontend IP of the installed HTTP Proxy. Customers who route their whole network through our Threat Protection Centers (Routed DSR) can create a proxy service using a Frontend IP from their own prefix (Customer Anycast IP range), without the need for any DNS changes mentioned in this document. This is called Route-to-Proxy.

To ensure a successful setup, the right staff members from your team should be available during the process.

* A proxy service can be created, installed, and set to protect an asset in approximately 5-10 minutes, if the following conditions are met:

  • The customer account is already set up
  • The customer has set a low TTL (time-to-live) at 120 seconds or less
  • It is an HTTP Proxy with TLS
  • The customer has already uploaded a certificate to the Threat Protection portal (portal.baffinbay.com).

Deploying HTTP Proxy services

An HTTP Proxy service is designed to protect a single HTTP service (ex. Website or API) against incoming threats. That includes the capabilities to decrypt and re-encrypt data, inspect clear-text payload, and apply Geo-fencing, Rate-limiting, and a Web Application Firewall. All proxy services have IP Reputation and Network DDoS protection by default.

Proxies are configured using assigned anycast IPs from Threat Protection’s or the your own prefixes. Proxy traffic is bidirectional through our Threat Protection Centers (TPCs). All traffic from our TPCs to your backend services is proxied. An X-Forward-For header and X-Real-IP header with the original client IP are always added for the HTTP Proxy service.

Benefits of HTTP Proxy Deployments

  • Quickly protect Internet-facing assets
  • Protection from DDoS attacks
  • Protection from known bad actors (IP Reputation)
  • Easy-to-use geo-fencing
  • Application layer protection
  • Always on protection
  • SSL inspection
  • Improve website performance