Artica Reverse Proxy Edition is designed to protect web services and enforce the security, speed and privacy of your web applications.
It approaches Layer 7 defense.
It use signature-based approaches by delivering security protections and operational improvements
Artica is designed to block new, unknown attacks by default, conducting advanced threat analysis on inbound content to detect and protect infrastructure from attacks.
The Reverse-proxy consists of receiving user requests and transferring them to one or more web servers.
The reverse-proxy is then between the clients and your websites.
With Artica Reverse-Proxy, make sure your website is protected from online threats while enjoying optimum speed.
With this advanced web security solution, you can protect your site against DDoS attacks, SQL injections, XSS attacks and much more.
What's more, this caching technology speeds up the loading of your site, delivering a fast, fluid user experience.
- Role-based access control (RBAC)
Role-based access control lets you restrict access rights to server features.
- The Template feature
Web service configuration has a multitude of parameters.
Templates allow you to replicate a specific configuration for new web services.
- Maintenance mode
Maintenance mode quickly blocks all requests to your website
and displays an apology page informing your visitors to come back later.
- Web site Vitrification
It provides offline site mirroring.
It scrapes configured backend websites, rewrites HTML
for local serving the cached content as static pages.
- Automatic configurations backups
This feature allows you to save the configuration set
built locally on disk so that you can restore it if you encounter any problems.
¶ Statistics and monitoring
- Nginx Memory Guard
Memory curves, watchdog hot restarts, nightly preventive restart and worker sizing of the reverse-proxy engine
- Prometheus Exporter for Artica Stats
Exposes a built-in Prometheus-compatible metrics endpoint on port 9925, providing real-time visibility into reverse proxy traffic.
- Connect an Artica reverse-proxy to the Artica SIEM
Stream requests, WAF hits and backend SLA from an Artica reverse-proxy to an Artica SIEM appliance over mutual TLS.
- Reverse-Proxy statistics - overall and per site
Every HTTP request passing through your reverse proxy is classified, counted, and visualized in real time.
- Global metrics
Per-service request statistics: yearly/monthly/daily trends, live requests-per-minute, and a one-click PDF report.
- Obtaining generic reverse-proxy metrics
Artica produces central data on the number of simultaneous connections and the number of requests.
- Obtaining reverse-proxy metrics per site
By default, Artica provides you with metrics on the number of requests and bandwidth used by each web service you have in production.
- Current active client connections
This feature delivers real-time, per-client visibility within Artica Reverse Proxy.
- Latencies metrics
Know exactly how fast your backends respond — Before your users complain
- Block bots crawling your websites
With the growth of social networks and AI systems, more and more bots crawl your websites.
These visits load your databases and page-rendering engines.
Artica provides mechanisms to limit excessive bot traffic, protecting resources and preserving performance.
- Prevent access to your web server using foreign domains
To prevent access to your web server through its public IP address or through unauthorized domain names, Artica can be configured with a default server that denies any request not targeting an explicitly configured domain.
- Dangerous Paths: block reconnaissance scanners
Detect and firewall-ban HTTP reconnaissance probes targeting dangerous paths such as /.env, /.git/ or forgotten backups.
- Firewall feature for Reverse-Proxy and Web services
The Firewall feature for Reverse-Proxy is designed to monitor accesses from and to your web services.
Especially what your server doing during outgoing connections.
- The Web Application Firewall
This feature provide protections against generic classes of vulnerabilities using the OWASP.
- Artica EdgeGuard
An enterprise-grade Web Application Firewall (WAF) that protects web applications against OWASP Top 10 attacks, bots, DDoS, and advanced threats.
It provides 145+ security modules, a hierarchical multi-tenant configuration, compliance reporting.
More details on security features in the security dedicated security section to this part.
The reverse-proxy features load balancing capability enabling connections to be transferred to the available web server.
- Setup multiple backends using load-balancing
Configure the load balancing method to efficiently distribute traffic among backend servers, making it an excellent choice for handling high traffic applications, microservices, and distributed architectures.
- The keepalive feature
The keepalive feature plays a crucial role in optimizing the performance and efficiency of network connections between the reverse-proxy and backends servers
- Redirect incoming requests from one port to another
Your virtual server listens on multiple ports, and you need to forward all requests from specific ports to a different one.
- Use specific DNS servers
Using Specific DNS servers in reverse-proxy brings several benefits, especially in dynamic environments where backend services or external resources may change IP addresses frequently
- Use an outgoing interface
This feature allows you to specify the source IP address that the reverse proxy will use when connecting to upstream servers, enabling you to choose which IP to use for outbound connections.
- Accept Proxy Protocol
When using the Artica Reverse Proxy behind a load balancer (such as PulseReverse), the Proxy Protocol allows the load balancer to transmit the original client’s source IP address and port to the backend web servers.
This information is essential, as it enables Artica Reverse Proxy to accurately monitor and log client activity at the proxy level.
- Backend Mirroring
Backend mirroring duplicates a copy of every incoming request to one or more additional backend servers, without waiting for or returning their responses to the client.
- Shadow backend
The Shadow backend mode turns a reverse-proxy website into a local sink
¶ Limits and bandwidth
- Setup a DoH gateway
The DoH gateway mode transforms a DNS service that only resolves UDP/TCP requests into a DNS Over HTTPs service.
- Setup a PHP Website
A PHP website is a Web service that runs on the reverse-proxy server, using a dedicated PHP engine (version 8.3.4) to provide dynamic websites using the PHP language.
- Manage static HTML web sites
Artica Reverse Proxy allows you to easily publish websites composed of static HTML content.
This feature is especially valuable when you need to deliver a website quickly and with minimal system resources. It is ideal for serving lightweight content such as maintenance pages, landing pages, or documentation sites…
- Reverse-Proxy For Artica Web Console
Artica's web console listens on a different port, but you can make it available as a traditional website by adding a dedicated reverse-proxy rule.
Caching through the reverse-proxy means you don't need to query your backend server for regularly requested objects, and enables the reverse-proxy to produce web pages even if your backend servers are unavailable.
- Statistics globally and per site
Every HTTP request passing through your reverse proxy is classified, counted, and visualized in real time.
You see exactly what your infrastructure is doing, right now, and how it has behaved over time.
- Connect an Artica reverse-proxy to the Artica SIEM
Stream requests, WAF hits and backend SLA from an Artica reverse-proxy to an Artica SIEM appliance over mutual TLS.
- HotLogs — Search & diagnose requests in the logs
Targeted search & diagnostics over the reverse-proxy access logs: filter, chart and export matching requests from the WebConsole.
- The Backend SLA feature
Continuously supervises the servers your reverse proxy forwards traffic to.
It measures whether each backend answers, how fast it answers, whether its TLS is sound, and whether it meets the availability target you expect from it
And it keeps that history so you can prove it.
- Turning to 503 error if system capacity exceeded
This feature monitors memory usage (including swap partition), processor load and average system requests response time of , as well as processor utilization...
- Reverse-proxy backend watchdog
This feature is designed to check the health of protected Web servers and send an alert if they are down or if an issue is discovered.
- Check your reverse configuration
Artica can check access from the machine itself. Two checks take place...
- Turn on debug mode on a website
The verbose mode allows you to discuss with ArticaTech's support team in case of problems encountered on a Web site.
- Search and display real-time requests
Real-time requests monitor section allows you to view and search for user requests to your web services
- Extracting Requests from Reverse-Proxy Legal Logs Storage
By extracting and analyzing request data from reverse-proxy logs, organizations can identify suspicious patterns, detect potential security threats, and mitigate attacks such as DDoS, brute force attempts, or unauthorized access attempts.
This proactive approach strengthens overall cybersecurity posture.
- Grafana and Prometheus
Using Grafana and the Prometheus Exporter allows you to monitor and visualize your Reverse-Proxy metrics in real-time.
This setup is particularly useful for gaining insights into server performance, traffic patterns, and resource utilization
¶ Maintain software / Exports / Imports