Our current architecture employs a tiered defense: an on-premises WAF (ModSecurity on nginx) performing detailed request inspection and mitigation, fronted by Akamai Prolexic for DDoS protection at the edge. While this layered security model is conceptually sound, I've observed a measurable increase in tail latency (p99) for clean traffic since implementing Prolexic. This has prompted an analysis of whether we are introducing redundant processing and unnecessary latency hops.
A simplified view of our request flow is now:
```
Client -> Akamai Prolexic (DDoS Scrubbing) -> Our WAF (ModSecurity Rule Evaluation) -> Application
```
The concern is that both systems are performing overlapping work, particularly in the initial phases of request analysis. Our ModSecurity core rule set (CRS) parses HTTP requests, normalizes encodings, and checks for malicious patterns. Prolexic, while primarily a volumetric DDoS solution, also includes its own set of proactive rule checks and bot mitigations that appear to perform similar parsing and inspection.
From a latency profiling perspective, I've measured two key degradations:
* **TLS Handshake RTT Increase:** Prolexic terminates TLS at its PoP. Our own WAF, sitting in our data center, then re-establishes a new TLS connection to the client (now proxied by Akamai). This adds a full round-trip for the inner TLS handshake, which is particularly impactful for users geographically distant from our primary data center, despite Akamai's edge.
* **Dual-Pass Inspection:** Both systems are performing HTTP protocol validation, header size checks, and basic anomaly detection. We are effectively paying the parsing and inspection penalty twice. While the absolute time for a single request might be in low milliseconds, under sustained load this dual-pass model increases CPU load on our WAF and contributes to latency variance.
My specific questions for the community are:
* Have you performed a structured analysis of rule overlap between Prolexic's proactive controls and a downstream WAF? Is there a recommended methodology to disable categories of inspection on one layer when it's confidently handled by the other?
* In practice, is it more performant to configure Prolexic in a "blind proxy" mode, where it forwards all traffic after basic volumetric filtering to our WAF for the actual security decisions? Or does Prolexic's value diminish if we disable its proactive rule engine?
* Are there measurable performance gains from moving our WAF ruleset *into* Prolexic (or Akamai's Kona WAF) and eliminating the on-premises WAF hop entirely, or does that simply shift the latency penalty to a different point in the chain?
I am currently instrumenting the request journey with high-resolution timing headers to quantify the latency contribution of each stage. Initial data suggests the dual TLS termination and repeated request parsing are the primary culprits. I welcome any similar analyses or architectural experiences from teams running layered perimeter defenses.
brianh