Web App Firewall protection for VPN virtual servers and authentication virtual servers
ns-aaatm-default-appfw-profile, ns-aaa-default-appfw-profile, and ns-vpn-default-appfw-profile. The profiles contain the associated built-in API specification files ns-aaatm-spec, ns-aaa-spec, and ns-vpn-spec to ensure that network traffic is secure and compliant with the API specifications.
Licensing requirements
Configure Web App Firewall protection
On the GUI
-
Navigate to Security > AAA- Application Traffic > Change authentication AAA settings.
-
On the Configure AAA Parameter page, configure WAF Protection.The following options are supported:
-
Disabled - When selected, Web App Firewall protection is not applied to any virtual server. By default, Web App Firewall protection is not set to any value.
-
AUTH – Protects the authentication virtual server.
-
VPN – Protects the VPN virtual server.
-
AUTH and VPN – Protects the authentication, traffic management, and VPN virtual servers.
-
-
Click OK.
On the CLI
set aaa parameter -wafProtection <DISABLED/AUTH/VPN>
-
The
set aaa parameter -wafProtection AUTHcommand protects the authentication virtual servers. -
The
set aaa parameter -wafProtection VPNcommand protects the VPN virtual servers. -
The
set aaa parameter -wafProtection AUTH VPNcommand protects the authentication, VPN, and traffic management virtual servers.
Configure security insights
-
Before you configure the security insights, as a pre-requisite, ensure that the ULFD mode and AppFlow feature are enabled. On the GUI, you can perform this step by navigating to System > Settings > Modes and Features. On the CLI, you can use the commands
en ns mode ULFDanden ns feature appflow. -
Ensure that your NetScaler instances are added in NetScaler Console. For details, see Instance management.
On the GUI
On the CLI
set aaa parameter -securityInsights <ENABLED/DISABLED>
Configure AppFlow® collector and analytics profile on the GUI
-
Navigate to System > Settings. In the Modes and Features section and enable the ULFD mode and the AppFlow feature.
-
Configure an AppFlow collector.
-
Navigate to Configuration > System > AppFlow > AppFlow Collectors. Configure the required parameters and click Create.
AppFlow collector -
-
Set the configured AppFlow collector to the analytics profile. In this example, the AppFlow collector is set to the built-in analytics profile
ns-aaa-vpn-appfw-analytics-profile.-
Navigate to Configuration > System > Profiles > Analytics Profiles. In the Basic details section, select the AppFlow collector on the Collectors field.
Analytics profile -
Configure AppFlow collector and analytics profile on the CLI
- add appflow collector col2 -IPAddress 10.146.77.19 -port 5557 -Transport logstream
- set analytics profile ns-aaa-vpn-appfw-analytics-profile -collectors col2 -type securityinsight
View the AppFlow records on NetScaler Console
-
On the NetScaler Console on-prem GUI, navigate to Security > Security Violations. In the WAF section, select the VPN or the authentication virtual server. For more details, see View application security violation details.AppFlow recordsFor a detailed view, select the URL in the Request URL field.AppFlow records
-
Apply the appropriate licenses to your VPN or authentication virtual server.
-
Verify if your virtual server is licensed.
-
In Settings > Analytics configuration section of the NetScaler Console GUI, select your virtual server and apply the licenses. For more details, see Manage licensing and enable analytics on virtual servers.
-
Configure relaxation rules
On the GUI
"GET:/oauth/idp/login" authentication endpoint URL:
-
Navigate to Security > NetScaler® Web App Firewall > Profiles.
-
Select the profile
ns-aaa-default-appfw-profile. -
Under Advanced Settings, click Relaxation Rules.
-
Select the REST API schema validation checkbox.
-
Navigate to the beginning of the Relaxation Rules section and click Edit.
-
Click Add.
-
On the REST API Schema Validation Relaxation Rule page, update the required fields and click Create.Relaxation rule
-
Under Advanced Settings, select Profile Settings.
-
In the Common Settings section, select the Enable Bypass List checkbox.
-
Go back to the Advanced Settings section and select Global Bypass/Deny List.
-
In the Global Bypass List section, click Add.
-
On the Create AppFirewall Bypass List Binding page, update the required fields and click Create.Relaxation rule
On the CLI
"GET:/oauth/idp/login" authentication endpoint URL:
bind appfwprofile ns-aaa-default-appfw-profile -restValidation "GET:/oauth/idp/login"
set appfwprofile ns-aaa-default-appfw-profile -bypasslist on
bind appfwprofile ns-aaa-default-appfw-profile -bypasslist "CLIENT.IP.DST.EQ(192.0.2.255)" -valueType expression
Debug logging
Mar 22 07:04:26 <local0.info> 192.0.2.4 03/22/2024:07:04:26 GMT 0-PPE-0 : default APPFW APPFW_SCHEMA_VALUE_INCORRECT 864 0 : 10.106.31.93 107-PPE0 - ns-aaa-default-appfw-profile Parameter value incorrect as per API Spec: (ns-aaa-spec) for Endpoint: (GET https://192.0.2.5/oauth/idp/login?client_id=test&response_type=code&scope=openid%20profile&redirect_uri=https%3A%2F%2Foauthrp.aaa.local%2Foauth%2Flogin&state=Y3R4PU9tNzJ5WkNlTGJaSVhBb1lXM21ZVm40N0ZfQ1JzNjM1OGhvWEpRWkpDVFV1ZkY5U1hoOV9Edndfa282bHZ1ejBqQUFRU0hsbnBJTzF5U0NjbThQdVlqbm1Lb01ESHk5aFVVS19WR0xiaTgtVE9GaHRZZVBYWWJ3Q2F6d2JoZk5QX3hlY09BY2t1NHJUYlFqODZiaHhaZkU3RVdzJTNEA) <blocked>
stat command displays the counters of the user requests blocked by the traffic management and authentication virtual servers:
stat aaa | grep -i blocked
Total AAA Waf blocked hits 0 15
Total AAATM Waf blocked hits 0 1
stat command displays the counters of API specification file:
stat apispec
API spec(s) Summary hits validate unmatched
ns-a...-spec 0 0 0
ns-aaa-spec 15 12 0
ns-vpn-spec 4 4 0
aaa 0 0 0
Dynamic update of the new API specification files provided by NetScaler
-
ns-aaatm-spec: This file performs API schema validation of the incoming requests to the traffic management virtual servers.
-
ns-aaa-spec: This file performs API schema validation of the incoming requests to the authentication virtual servers.
-
ns-vpn-spec: This file performs API schema validation of the incoming requests to the VPN virtual servers.
-
Navigate to Security > NetScaler Web App Firewall > Imports > API Spec Import.
-
Select the API specification file and click Edit.
-
On the API Spec Import Object page, click File.
-
Upload the new API schema file and click Continue.Notes:
-
Do not rename API specification files that NetScaler provides.
-
Ensure that the Encrypted checkbox is selected. API specification import
-
-
Click Done.
Limitation
References
-
For more information about the NetScaler Web App Firewall feature, see Introduction to NetScaler Web App Firewall.
-
For more information about the AppFlow feature, see AppFlow.
-
For FAQ details, see Authentication, Authorization, and Auditing.