> For the complete documentation index, see [llms.txt](https://waf-doc.inext.checkpoint.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://waf-doc.inext.checkpoint.com/getting-started/deploy-enforcement-point/waf-as-a-service-waf-saas.md).

# WAF-as-a-Service (WAF SaaS)

## Overview

Check Point WAF SaaS delivers the full security capabilities of Check Point WAF—without the need for complex deployment. It simplifies protection by routing your domain’s traffic through Check Point's cloud-based service, where traffic is inspected and forwarded securely to your internal servers. In addition to streamlined deployment, WAF SaaS enhances your security posture with advanced DDoS protection.

The service operates as a reverse proxy, inspecting incoming traffic and applying Check Point WAF security policies before passing requests to your origin servers.

<figure><img src="/files/QUwSyc3BhidZYvsYe160" alt=""><figcaption></figcaption></figure>

## Check Point WAF SaaS Points of Presence (PoPs)

When setting up your Check Point WAF SaaS account, you selected a **data region**. This defines your **data residency**—the physical or geographic location where your data is stored—and determines the region of the **Infinity Portal** where you can view and manage configurations and logs.

For more information, see:&#x20;

{% content-ref url="/pages/vEPYjTAMpjJWA0oAZhy2" %}
[WAF-as-a Service (WAF SaaS)](/concepts/waf-as-a-service-waf-saas.md)
{% endcontent-ref %}

### Deployment

#### Prerequisites

* **DNS Ownership:** You must control the DNS settings for the domain you’re protecting.
* **Origin Accessibility**\
  · Whitelist all Check Point WAF SaaS IPs on your internal web server.\
  · If you’ve just spun up a new server, you may temporarily expose it publicly for this initial phase—but *must* lock it down immediately after WAF goes live.

#### Instructions:&#x20;

To protect your web application with **Check Point WAF SaaS**, follow these steps:

#### Step 1: Create a New Asset&#x20;

Define the website you want to protect.

* Enter the **public URLs** (e.g. `www.example.com`)
* Provide the **upstream origin URL** (e.g. your internal server’s IP or hostname)

{% hint style="info" %}
Depending on your license, Check Point WAF SaaS does not impose any limitation on the number of root domains it can support.
{% endhint %}

{% hint style="success" %}
If you want to integrate your WAF with an existing AWS CloudFront follow the steps here:

[Integrating WAF SaaS with AWS CloudFront](/getting-started/deploy-enforcement-point/waf-as-a-service-waf-saas/integrating-waf-saas-with-aws-cloudfront.md)
{% endhint %}

<div data-full-width="false"><figure><img src="/files/bHCUF6HjXrsrrA1EMsYR" alt="" width="375"><figcaption></figcaption></figure></div>

#### Step 2: Connect to a WAF SaaS Profile

Link your asset to a **new or existing WAF SaaS profile**.\
This profile contains your security policies and PoP settings, such as the geographical region in the world where you traffic will be processed.

<figure><img src="/files/z9rpG0rY41T6rpddRafj" alt="" width="375"><figcaption></figcaption></figure>

{% hint style="info" %}
You can configure multi-region deployment for this domain. See [*How to Configure Multi-Region Deployment*](/how-to/configure-multi-region-deployment-in-waf-saas.md) for more details.
{% endhint %}

**3. Select a Certificate Management Option**

Choose how SSL/TLS certificates will be handled:

* **Check Point Managed -Managed Certificate**\
  Let us generate and renew your certificates automatically using Let’s Encrypt.
* **Bring Your Own Certificate**\
  Upload an existing certificate and private key (PEM format).

<figure><img src="/files/LdFC1HAjrF0VMYHqIyVR" alt="" width="375"><figcaption></figcaption></figure>

#### Step 4: Complete Certificate Configuration

Follow the detailed instructions based on the option selected in Step 3:

{% tabs %}
{% tab title="Certificates Managed by Check Point" %}
When using **Check Point ‑managed certificates**, setup is mostly automatic. However, for **each domain** protected by **WAF SaaS in a specific region**, you must complete the following steps to ensure traffic is fully secured.

{% hint style="success" %}
**When to perform these steps**

* When creating a new asset
* When adding new domains to an existing asset
* When attaching a WAF SaaS profile to an asset that wasn’t previously protected
* When editing a domain (remove the old one *after* adding and configuring the new one)
  {% endhint %}

**Prove Domain Ownership**

To authorizes Check Point to issue certificates for your domain using Let’s Encrypt, Follow the steps bellow:

1. In the Infinity Portal, go to **Policy → Profiles**.
2. Select the **Check Point WAF SaaS profile** created during the Asset setup.
3. Find the domain marked as “Pending Action” and click it.
4. Copy the **DNS CNAME record** shown under the domain ownership verification step.
5. In your DNS provider’s console, **add the CNAME record** with the name and value provided.

{% hint style="warning" %}
You must complete this step **for each domain** individually (e.g. `www.myapp.com` and `api.myapp.com`)
{% endhint %}

{% hint style="success" %}
When you onboard a new domain that's already covered by an existing wildcard certificate, Check Point WAF SaaS automatically attaches that certificate instead of issuing a new one — onboarding completes immediately instead of waiting on issuance and validation.
{% endhint %}

<figure><img src="/files/JwhkHWi00g0lBkewxpl4" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/7MfzOK1f64Zx8Lvgd2iZ" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Bring Your Own Certificate (BYOC) " %}
While Check Point WAF SaaS offers managed public SSL/TLS certificates signed by Let’s Encrypt, you may choose to use your **own certificate and private key,** ideal for compliance needs or existing certificate infrastructure.

{% hint style="success" %}
Your private key is **end-to-end encrypted** during upload, ensuring complete confidentiality and security.
{% endhint %}

To configure HTTPS traffic with your own certificates, follow the steps below:

#### Upload Certificate and Private Key

1. In the Infinity Portal, navigate to **Policy → Profiles**.
2. Select the **Check Point** **WAF SaaS profile** linked to your asset.
3. For each domain listed, click on it and:
   * Upload the **public certificate** (PEM format)
   * Upload the **private key**
   * Ensure the certificate includes the **full chain**

{% hint style="success" %}
**Reusing an Uploaded Certificate**\
Instead of uploading a new certificate for every domain, select **My certificates** in a domain's **Certificates & Domain Management** panel to open **Select Certificate** — a list of certificates you've already uploaded, showing each one's name, type (Specific/Wildcard), and expiration date. From here you can select an existing certificate to attach to this domain, upload a new one, or delete a certificate you no longer need.
{% endhint %}

{% hint style="warning" %}
Unlike Check Point-managed certificates, BYOC certificates are not auto-renewed. As a certificate approaches expiration, the portal displays a live countdown warning (e.g. "This certificate will not be auto-renewed. Please renew it within the next N days."). Renew and re-upload your certificate before it expires to avoid a validation failure or downtime.
{% endhint %}

<figure><img src="/files/PYAJQLuncOJOOXP95xnQ" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/WmhfVGodPkFLPwxZ4Akg" alt=""><figcaption></figcaption></figure>
{% endtab %}
{% endtabs %}

You can switch a domain from BYOC to a Check Point-managed certificate (or vice versa) at any time, with no downtime — the previous certificate stays active until the new one validates.

#### Step 5: Connect your domain to WAF SaaS

{% hint style="warning" %}
Before performing this stage, disable any existing AWS CloudFront configuration for your website's address if you have any.
{% endhint %}

Once the previous step is completed, a new **CNAME value** will be generated (this may take up to 30 minutes).

1. In your DNS configuration, replace the existing CNAME record for your domain with the **new CNAME value** issued by Check Point.

<figure><img src="/files/po09MsUcN5sreaYHwuaG" alt=""><figcaption></figcaption></figure>

#### Step 6: Allow WAF SaaS to Access Your Origin Server

To ensure smooth traffic flow between WAF SaaS and your internal web server:

1. **Allow incoming traffic** from the IP addresses provided in the **WAF SaaS deployment form**.
2. **Do not remove** existing access rules until:
   * 72 hours have passed (to allow full DNS propagation), and
   * You have confirmed successful traffic flow through WAF SaaS.

{% hint style="info" %}
If the origin was previously publicly accessible, restrict access to only WAF SaaS IPs after DNS switchover.\
If you were using another reverse proxy, consider removing its IPs from the access list after confirming the switch.
{% endhint %}

<figure><img src="/files/2CqkEtdNm2CAhl5VAjlR" alt=""><figcaption></figcaption></figure>

#### **Step 7: Test Access to Your Site**

After completing the above steps:

* Confirm that the website is reachable over HTTPS.
* Verify that traffic is flowing through WAF SaaS (you can check headers or logs in the Infinity Portal).
* Double-check that your origin server is **no longer publicly accessible** (unless intentionally exposed).

{% hint style="info" %}
While DNS changes typically take just a few hours, allow up to **72 hours** for full global propagation before making final changes.
{% endhint %}

{% hint style="danger" %}
Make sure you have not left a publicly exposed domain in your previous environment!
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://waf-doc.inext.checkpoint.com/getting-started/deploy-enforcement-point/waf-as-a-service-waf-saas.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
