Load balancing Metaswitch EAS WAF Gateway
Benefits of load balancing Metaswitch EAS WAF Gateway
Load balancing Metaswitch EAS WAF Gateway provides enhanced security and service resilience:
- High Availability (HA): Load balancing ensures that the Metaswitch EAS (Enhanced Application Server) service remains continuously available even if one component fails. The load balancer continuously monitors the health of the Metaswitch EAS/WAF gateway instances. If an instance becomes unresponsive or unhealthy, the load balancer automatically and immediately redirects all incoming traffic to the remaining healthy instances. This failover capability minimizes service disruption, allowing for maintenance, upgrades, or unexpected failures without impacting end-user access to services like CommPortal.
- Scalability and performance optimization: Load balancing allows the Metaswitch EAS infrastructure to handle increasing user demand and traffic spikes efficiently. It intelligently distributes client requests across a pool of multiple EAS/WAF gateway instances. This prevents any single server from becoming a bottleneck or being overloaded, ensuring consistent and fast response times for all users. It also enables horizontal scaling, meaning you can easily add more EAS/WAF instances to the pool to meet growing demand (e.g., during high-traffic events) and remove them when demand subsides, optimizing resource usage and cost.
- Enhanced security and threat mitigation: By placing the WAF gateway behind a load balancer, you enhance its protective capacity. While the WAF provides application-layer security against attacks like SQL injection and XSS, the load balancer acts as an initial shield. It can distribute and absorb Distributed Denial of Service (DDoS) attacks across multiple WAF instances, preventing a single instance from being overwhelmed and ensuring the core Metaswitch EAS remains protected and operational. The load balancer can handle the SSL/TLS decryption and encryption for incoming and outgoing traffic. This offloads computationally intensive processing from the Metaswitch EAS servers, dedicating their resources to core application logic while maintaining secure, encrypted communication between the client and the network edge.
About Metaswitch EAS WAF Gateway
The Metaswitch EAS WAF Gateway is a specialized security solution designed to protect the Metaswitch Enhanced Application Server (EAS) and its customer-facing web applications, such as CommPortal, from cyberattacks.
It is typically deployed as a Web Application Firewall (WAF) on a load balancer appliance (often from a partner like Loadbalancer.org) that sits in front of the EAS servers.
Why Loadbalancer.org for Metaswitch EAS WAF Gateway?
Metaswitch and Loadbalancer.org have a long-standing partnership for the implementation of Metaswitch EAS. Whether deployed as hardware or virtualized, the Loadbalancer.org solution ensures Metaswitch EAS is highly available and highly secure.
The Loadbalancer.org appliance includes a fully integrated industry standard Web Application Firewall (WAF) by default. Although a wide number of 3rd party commercial hardware and virtual WAFs are currently available, these are typically not configured to meet the specific and ever-changing threats faced by communication service providers. Therefore, Metaswitch recommend that customers looking to enhance their network security upgrade to a Loadbalancer.org WAF Gateway.
Developed collaboratively with Metaswitch and based on real-world customer experience, the Loadbalancer.org solution explicitly addresses known threats in the Metaswitch installed base using custom WAF rules specifically developed by Loadbalancer.org to protect a Metaswitch EAS deployment. This is described in detail in the attached deployment guide.
How to load balance Metaswitch WAF Gateway
The EAS services that need to be protected
The Loadbalancer.org WAF solution for Metaswitch EAS is designed to protect:
- The CommPortal login page;
- (optionally) the SIP provisioning services (SIP-PS and PPS) on the EAS nodes
For each service provided by a Metaswitch deployment that needs to be protected by putting a WAF gateway in front of it, up to three linked elements need to be created:
- TLS/SSL termination VIP (only required for services handling encrypted traffic, i.e. HTTPS)
- WAF gateway (always required)
- Layer 7 VIP (always required) In general, for each service that needs protecting, a chain of the above elements must be created on a Loadbalancer.org appliance.
- The specifics can vary slightly depending on the deployment scenario, as described in detail in the deployment guide below.
