Configuring Web App Firewall profiles
To configure a Web App Firewall profile by using the command line
-
set appfw profile <name> <arg1> [<arg2> ...]where:-
<arg1>= a parameter and any associated options. -
<arg2>= a second parameter and any associated options. -
... = additional parameters and options.
For descriptions of the parameters to use when configuring specific security checks, see Advanced Protections. -
-
save ns config
Example
pr-basic. This command enables blocking for those actions while making no other changes to the profile.
set appfw profile pr-basic -crossSiteScriptingAction block -SQLInjectionAction block
Bind relaxation rule to a Web App Firewall profile
To bind security exemption or relaxation rules by using the CLI
bind appfw profile <name> ((-startURL <expression> [-resourceId <string>]) | -denyURL <expression> | (-fieldConsistency <string> <formActionURL> [-isRegex ( REGEX | NOTREGEX )]) | (-cookieConsistency <string> [-isRegex ( REGEX | NOTREGEX )]) | (-SQLInjection <string> <formActionURL> [-isRegex ( REGEX | NOTREGEX )] [-location <location>] [-valueType <valueType> <valueExpression>....
To bind security exemption or relaxation rules by using the GUI
-
Navigate to Security > NetScaler Web App Firewall > Profiles.
-
In the details pane, select a profile and click Edit.
-
In the NetScaler Web App Firewall Profile page, click Relaxation Rules from the Advanced Setting section.
-
In the Relaxation Rules section, click StartURL and click Edit.
-
In the Start URL Relaxation Rules page, click Add.
-
In the Start URL Relaxation Rule page, set the following parameters:
-
Enabled. Select the check box to enable the relaxation rule
-
Start URL. Enter the regular expression value
-
Comments. Provide a short description about the relaxation rule.
-
-
Click Create and Close.
To configure a Web App Firewall profile by using the GUI
-
Navigate to Security > NetScaler Web App Firewall > Profiles.
-
In the details pane, select the profile that you want to configure, and then click Edit.
-
In the Configure Web App Firewall Profile dialog box, on the Security Checks tab, configure the security checks.
-
To enable or disable an action for a check, in the list, select or clear the check box for the action.
-
To configure the parameters for the security checks in the list, select the check box and click Active Settings.
-
To review log entries for the selected security check, select the check box and click Logs. You can use this information to determine the security checks that match attacks, so that you can block the traffic for the security checks. You can also use the information to determine the checks that match legitimate traffic, so that you can configure an appropriate exemption to allow those legitimate connections. For more information about the logs, see Logs, Statistics, and Reports.
-
To completely disable a check, in the list, clear all of the check boxes to the right of that check.
-
-
On the Settings tab, configure the profile settings.
-
To associate the profile with the set of signatures that you previously created and configured, under Common Settings, choose that set of signatures in the Signatures drop-down list.Note:You must use the scroll bar on the right of the dialog box to scroll down to display the Common Settings section.
-
To configure an HTML or XML Error Object, select the object from the appropriate drop-down list.Note:You must first upload the error object that you want to use in the Imports pane. For more information about importing error objects, see Imports.
-
To configure the default XML Content Type, type the content type string directly into the Default Request and Default Response text boxes, or click Manage Allowed Content Types to manage the list of allowed content types. >>More....
-
-
If you want to use the learning feature, click Learning, and configure the learning settings for the profile, as described in Configuring and Using the Learning Feature.
-
Click OK to save your changes and return to the Profiles pane.
Confidential fields in WAF profile
-
Navigate to Security > NetScaler Web App Firewall > Profiles.
-
Select a profile and click Edit.
-
In Advanced Settings, click Confidential Fields.
-
Click Add.
-
Enter values for the following parameters:
-
Form Field Name*
-
Action URL*
-
Comments A
*indicates a mandatory field
-
-
Click Create.
-
Click Done.