Uncategorized

Using Progress Kemp LoadMaster as an API Gateway

Using Progress Kemp LoadMaster as an API Gateway

Using Progress Kemp LoadMaster as an API Gateway

Marc Andreessen famously stated that software was eating the world—a correct observation. From the perspective of the second half of 2022, there is a good case for a comparable statement. Namely that applications are transforming business.

Almost every end-user business interaction with an IT system happens via an application running on the Web, a PC, or a mobile device. All these applications communicate over the network with backend servers and other infrastructure. In most cases, they do this via various APIs (Application Programming Interfaces) that allow developers to hook into functionality to read, write, and process data.

The proliferation in applications of all types, plus their heavy use of APIs, has not gone unnoticed by cybercriminals. Attackers are actively targeting API weaknesses as part of their broader cyberattack strategy. The Verizon 2022 Data Breach Investigations Report shows that attacks targeting API vulnerabilities are one of the fastest-growing attack methods used by cybercriminals.

Great, I hear you say; we need to include another part of our IT infrastructure in cybersecurity defence planning. Sadly, that is correct. But thankfully, there are protections that build upon existing networking solutions you probably already have in place. Such as Progress Kemp LoadMaster, which can be used as an API Gateway in addition to delivering load balancing, application delivery management, TLS/SSL offloading, and the many other functions it provides.

What is an API Gateway, and What Does It Do?

The APIs that applications use to communicate are typically using the HTTPS protocol. This means that load balancers operating via that protocol are ideally positioned to interact with API traffic flowing over the network.

It's been clear for as long as web applications have used APIs to communicate with other systems that management was needed to control how the APIs function. This management covers items like authentication for connections, rate limiting (throttling) the number of API calls that can be made in a certain period, and TLS/SSL encryption to ensure API traffic is secure.

API gateways were developed to deliver these and additional functionality alongside APIs. Deploying API gateways allows for the provision of controlled and easily identifiable edge endpoints that take incoming API calls and route them to the servers running the applications. If you are familiar with load balancing, API Gateway functionality and load balancing will sound very similar, which is why it makes perfect sense to deliver API gateway services via LoadMaster.

LoadMaster API Gateway Functionality

LoadMaster has the features to deliver API gateway functionality. Typically an API gateway will need to provide:

  • Authentication of requests
  • Filtering and routing of requests
  • Termination of TLS/SSL
  • Caching of data
  • Rate limiting
  • Logging and metrics

All of which fall within the feature set of LoadMaster. The diagram below outlines how organisations could deliver load balancing and API gateway functionality from LoadMaster application delivery controllers running on-premise or in the cloud.

Using Progress Kemp LoadMaster as an API Gateway

The answer to the question "should I have separate API gateways or combine the functionality with load balancing?" will vary depending on each organisation's application delivery landscape and the APIs in question. Progress Kemp can work with you to determine the best deployment model based on your needs.

Find Out More

You can read more on API gateways and LoadMaster via the article "How To Use A Load Balancer As An API Gateway" on the Progress Kemp blog.

If you have any questions after reading the blog post and any relevant articles it links to, then contact us, and we'll put you in contact with an appropriate expert to discuss your needs and answer any queries you have.