Configure Multi-Region Deployment in WAF SaaS
Last updated
Was this helpful?
WAF SaaS supports deployment across multiple regions to improve service resiliency and availability.
The default multi-region deployment in WAF SaaS is a failover-based configuration managed by Check Point.
Create two WAF SaaS profiles for the same protected application.
Both profiles receive the same DNS hostname.
One region serves as the primary region.
The second region serves as the standby region.
Check Point manages traffic failover between the regions automatically behind the scenes.
Traffic may be redirected to the secondary region if the primary region:
Is unreachable
Does not respond within the expected time
Returns specific server-side errors
Failover is supported only for the following HTTP methods:
GET
HEAD
OPTIONS
When the primary region becomes healthy again:
Traffic is automatically routed back to the primary region
The secondary region returns to standby mode
The failover behavior described above is not supported for special configurations, including:
Protecting a root (apex) domain which were onboarded prior to May 25th, 2026
Using custom ports
Protecting a domain with an existing CDN distribution (for example, CloudFront)
In these cases, each WAF SaaS profile receives a different DNS hostname and traffic is routed directly to the specific profile region.
Customers requiring multi-region traffic handling for these configurations should contact Check Point.
Last updated
Was this helpful?
Was this helpful?