Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
YouTube Security VideosNutanix advances legacy and AI app management with AMD(01.10.2026 um 16:00 Uhr)
•
YouTube Security VideosPC-WELT: 32 TB SSD-Speicher in der HMX 6!(01.10.2026 um 16:15 Uhr)
••••
Videos & KonferenzenPC-WELT: 32 TB SSD-Speicher in der HMX 6!(01.10.2026 um 16:15 Uhr)
••
Sicherheitslücken (CVE)USN-8857-1: KCoreAddons vulnerability(01.10.2026 um 12:48 Uhr)
•••
YouTube Security VideosNutanix advances legacy and AI app management with AMD(01.10.2026 um 16:00 Uhr)
•
YouTube Security VideosPC-WELT: 32 TB SSD-Speicher in der HMX 6!(01.10.2026 um 16:15 Uhr)
••••
Videos & KonferenzenPC-WELT: 32 TB SSD-Speicher in der HMX 6!(01.10.2026 um 16:15 Uhr)
••
Sicherheitslücken (CVE)USN-8857-1: KCoreAddons vulnerability(01.10.2026 um 12:48 Uhr)
•••
Intelligence View
⚡ tsecurity.de Intelligence

How to Implement Upstream Failover in SafeLine WAF

Article Source: https://juejin.cn/post/7296076144448618506 To further enhance our internal network security, we added the open-source community version of…

Beitrag
0
Seite
0
↗ Quelle (dev.to)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!

Article Source: https://juejin.cn/post/7296076144448618506



To further enhance our internal network security, we added the open-source community version of SafeLine WAF on top of our existing hardware WAF as a software WAF at the application layer. This enabled a multi-layered WAF protection architecture.



After further exploration, we found that SafeLine WAF's upstream proxy forwarding is based on Tengine. This gave us the idea to use SafeLine not only for WAF protection but also for load balancing and automatic failover.






Step 1: Prepare a HTTP Server for test



We created a simple HTTP server with a /status route returning HTTP 200. Here's a basic Go example:




package main

import (
"os"
"fmt"
"net/http"
)

func Hello1Handler(w http.ResponseWriter, r *http.Request) {
fmt.Fprintf(w, "I am 11111")
}

func Hello2Handler(w http.ResponseWriter, r *http.Request) {
fmt.Fprintf(w, "I am 22222")
}

func check(w http.ResponseWriter, r *http.Request){
fmt.Fprintf(w, "check")
}

func main () {
if len(os.Args) > 1 {
http.HandleFunc("/hello", Hello1Handler)
http.HandleFunc("/status", check)
http.ListenAndServe(":8001", nil)
} else {
http.HandleFunc("/hello", Hello2Handler)
http.HandleFunc("/status", check)
http.ListenAndServe(":8002", nil)
}
}






Start two servers on ports 8001 and 8002 respectively.



Image description






Step 2: Create an App in SafeLine



Create a new application in SafeLine and set the upstream server to the first node (8001).



Image description



Verify that requests are correctly proxied to the HTTP server.



Image description






Step 3: Modify SafeLine Nginx Configuration



Locate the configuration files in:




/data/safeline/resources/nginx/sites-enabled






There will be several configuration files, named in the format: IF_backend_*



Each new app creates a file named like IF_backend_*.



Identify the correct file by checking the listening port using cat.



In my case, the file is IF_backend_2. Then start modifying the configuration inside this file.






Add a New Upstream Server



Image description



Configure load balancing based on health checks. The following is just a basic setup — you can modify or add configurations according to your specific needs.



Image description






Step 4: Test and Reload Configuration



Check the Nginx config:




docker exec safeline-tengine nginx -t






If you get the following output, it means the configuration test passed.

Image description



Restart SafeLine’s Nginx:




docker exec safeline-tengine nginx -s reload









Step 5: Test the Failover





  • Load Balancing Test: With equal weight (1), requests are distributed evenly across the two nodes.



Image description





  • Failover Test:
    Stop the HTTP server on port 8002.



Image description



After refreshing the page, you’ll see that all requests are now routed to the HTTP server on port 8001.



Image description






Conclusion



SafeLine’s built-in Tengine (Nginx) includes rich modules and can be configured for common load balancing and failover use cases. This setup enhances both availability and security, making SafeLine a robust choice for enterprise-grade web application protection.




SafeLine Website:https://ly.safepoint.cloud/ShZAy9x

Discord:https://discord.gg/dy3JT7dkmY

Github:https://github.com/chaitin/SafeLine


Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten How to Implement Upstream Failover in SafeLine WAF

Thematisch verwandte Begriffe: Implement, Upstream, Failover, SafeLine · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag