In a recent Technical Kemping webinar, I discussed how the history and maturity of the now 25-year-old Progress® Kemp® LoadMaster® solution make it a hardened product that can help organizations of all sizes secure their business applications.
I outlined that the value of LoadMaster security capabilities comes from its reliability, thanks to its time-tested code, while enabling security teams and systems administrators to deploy its security features via a layered approach that helps deliver the security features modern applications need.
The webinar, which you can watch on demand via the link below, covers the history of the LoadMaster solution, core load balancing concepts, the security stack built into LoadMaster, redundancy options and includes a live demo of deploying a new high availability (HA) pair from scratch. Read on for a breakdown of these topics.
Progress is a long-standing, NASDAQ-listed IT company with a broad portfolio that includes infrastructure products such as the Progress Chef DevOps platform, the LoadMaster solution and Progress Flowmon security software, along with separate digital experience (DX) and application experience (AX) business lines. Many people use Progress-built technology without realizing it.
The LoadMaster platform includes multiple deployment options, including virtual, hardware and cloud. Because the solution is focused on securely load balancing applications, the LoadMaster solution has a better price-to-throughput ratio than competitors who often inflate costs with non-core functionality.
The design goal over the lifetime of the product has remained consistent: deliver invisible technology with a visible impact. Organizations only need to set the LoadMaster product up once and it keeps working with minimal intervention for years.
Server load balancing deployments typically serve as a reverse proxy in front of application servers, handling access, authentication, availability, scalability and resilience. The LoadMaster load balancer determines where client traffic should go, continuously monitors server health, reroutes traffic if a server fails or is busy and can handle TLS/SSL encryption by offloading this burden from application servers.
Global Server Load Balancing (GSLB) extends the load balancing concept across geographically distributed sites, whether that means data centers in different cities or two LoadMaster deployments on the same campus network. GSLB operates at the DNS level but goes beyond standard DNS server redundancy. For example, instead of returning a static list of targets, the load balancing solution health-checks each destination before fulfilling an access request and can apply routing rules based on client subnets.
In the webinar, I framed LoadMaster security capabilities around the “onion model,” the idea that no single control stops every attack, so the goal is to put as many defensive layers as possible between the clients and the application.
The layers were outlined in order:
⁃ GSLB with IP reputation blocking stops known bad actors from getting a DNS lookup record at all.
⁃ Web Application Firewall (WAF) with IP blocking catches anything that gets past the first layer.
⁃ Core WAF rules inspect traffic for known threats and other patterns, dropping the connection when something seems untoward.
⁃ Pre-authentication blocks anyone who can’t supply known access credentials. It can use LDAP, RADIUS, OIDC or SAML against a local or cloud identity provider.
⁃ LoadMaster content rules add fine-grained conditions, such as requiring a specific subnet and user group membership before granting access to a given destination.
⁃ Rate limiting caps connections per server, per virtual service or globally, protecting against flooding attacks. Note that dedicated upstream network-based DDoS protection is still recommended.
Combined, these layers create what we call a zero-trust access gateway, built entirely from already-available LoadMaster features.
The LoadMaster WAF uses the same core rule set as the WAF engines used by Amazon and Google, protecting against the OWASP Top 10. Let’s be clear about the WAF’s scope: it is not a replacement for a perimeter firewall. It inspects HTTP and HTTPS traffic and adds value in environments where the perimeter firewall allows HTTP/HTTPS traffic through without inspecting the payload for injection attempts or other threats. The WAF inspects traffic against its rule set and drops a connection if anything exceeds a configured threat threshold.
Content rules let administrators route access traffic based on directory, hostname, protocol, header or source IP. They can also rewrite URLs and host headers and modify request and response data content. I walked through concrete security use cases, including blocking a specific source subnet outright and blocking traffic containing cookies tied to a known exploit.
⁃ High availability (HA) - An active-passive pair with bidirectional configuration sync. This remains the standard, most widely used setup.
⁃ GSLB balancing - Active-passive or active-active across multiple sites, syncing only DNS resolution and health check data rather than full configuration. LoadMaster GSLB is also available as a standalone product named GEO.
Note that the previously available Clustering redundancy option that I mentioned in this session was deprecated on July 1, 2026. Read more about why and your options in this explanatory article.
A few other LoadMaster capabilities worth highlighting came up during the webinar:
⁃ Automated Certificate Management Environment (ACME) support for automated certificate renewal through Let’s Encrypt or DigiCert. A timely feature as standards bodies reduce certificate lifespans. The Certificate Authority/Browser Forum has agreed to reduce TLS/SSL certificate lifespans to 47 days by March 2029. All the major browser providers and other interested parties supported the plan for the gradual reduction in certificate lifespan.
⁃ Kubernetes ingress controller functionality, letting LoadMaster automatically scale virtual services alongside pod scaling while applying the same WAF, rate limiting and pre-authentication controls in front of Kubernetes workloads.
⁃ Network telemetry, where the LoadMaster solution acts as a probe and exports flow data in IPFIX format to tools like the Flowmon network obervability platform or other, similar solutions.
LoadMaster 360 provides a single dashboard view across an entire LoadMaster estate, whether deployed on-premises, in the cloud or in a hybrid environment. It gathers and displays application status, certificate expiry information (including intermediate and root certificates), application delivery incidents, authentication history data and advanced WAF activity, including top triggered rules and blocked request counts.
We are actively extending the LoadMaster 360 platform, with plans to centralize ACME certificate management so a single push can update certificates across multiple LoadMaster instances.
I closed the webinar with a live build of a new HA pair, covering licensing, hostname changes, time zone and NTP configuration, network setup, restricting SSH access to a single interface, LDAP-based admin authentication and HA pairing with a shared virtual IP. I then created a virtual service, applied TLS/SSL offloading and enabled the WAF live, demonstrating how individual rule triggers accumulate points toward a configurable threshold before a request is blocked.
The LoadMaster USP remains consistent: a load balancer that has evolved into a full application delivery controller without sacrificing the reliability that has made it a fixture in production environments for 25 years. Security features such as WAF, pre-authentication and content rules provide a genuine zero-trust layer without bolting on separate products, and LoadMaster 360 consolidates an entire LoadMaster estate in a single view as deployments become more complex.
Ready to see it in action? Access a free trial:
⁃ Easy to deploy and configure - Use configuration templates and deployment guides to get up and running quickly.
⁃ Superb customer support 24/7 - Experience our renowned technical support with full access during your trial.
⁃ Platform ubiquity - Kemp LoadMaster supports more platforms: hardware, virtual, cloud or bare metal.