Dynamic profiling
-
HTML SQL injection
-
HTML Cross Site scripting
-
Field format
-
Start URL
-
Content-type
-
Field formats
-
CSRF form tagging
-
Cookie consistency
-
Deny URL
-
Buffer Overflow
-
Credit Card
-
Content-type protection
-
JSON Cmd Injection protection
Configure dynamic profiling by using the NetScaler command interface
-
Configure dynamic learning
-
Configure auto deployment grace period
Configure dynamic learning
set appfw profile <profile_name> dynamicLearning <security_checks>
Example
set appfw profile test1 dynamicLearning SQLInjection CrossSiteScripting fieldFormat startURL
Configure auto deployment grace period
set appfw learningsettings <profile name> -crossSiteScriptingAutoDeployGracePeriod <seconds>
set appfw learningsettings <profile name> fieldFormatAutoDeploymentGracePeriod <seconds>
set appfw learningsettings <profile name> SQLInjectionAutoDeploymentGracePeriod <seconds>
set appfw learningsettings <profile name> –startURLAutoDeployGracePeriod <seconds>
Example
set appfw learningsettings test1 –crossSiteScriptingAutoDeployGracePeriod 30
set appfw learningsettings test1 –startURLAutoDeployGracePeriod 7
set appfw learningsettings test1 –fieldFormatAutoDeploymentGracePeriod 10
set appfw learning settings test1 –SQLInjectionAutoDeploymentGracePeriod 12
Configuring dynamic profiling by using the NetScaler GUI
-
Navigate to Security > NetScaler Web App Firewall > Profile.
-
In the details pane, select a profile and click Edit.
-
In the NetScaler Web App Firewall page, click Dynamic Profiling under Advanced Settings.
-
In the Dynamic Profiling section, select a security check and click Edit.
-
In the Dynamic Profiling and Learning Settings page, set the grace period the security check.Dynamic profiling section
-
Click OK and Done.
Export and import of relaxation rules
How to export and import relaxation rules
-
You must first export the dynamic profiling-based data. For this, the export option is available for the relaxation rules in the WAF profile. When you select this option, you export the dynamic profiling relaxation rules and regular relaxation rules. You can use the export option to download the configuration as a compressed bundle on the appliance.
-
Once you have exported the data from the staging environment, you must import it to another NetScaler appliance. For this, you must use the import option available in the relaxation rules of the WAF profile. When you select this option, the appliance imports the specified relaxation rules bundled and restores it to the WAF profile of the selected appliance.
Import archived relaxation rules file by using CLI
import appfw archive <src> <name> [-comment <string>]
<protocol>://<host>[:<port>][/<path>] “name”: Indicates name of archive. “comment”: Comments associated with this archive.
restore appfw profile <archivename> [-relaxationRules] [-importProfileName <string>] [-matchUrlString <string>] [-replaceUrlString <string>] [-overwrite] [-augment]
archivename: Indicates source for tar archive. This is a mandatory argument. “relaxationRules”: Option to import all appfw relaxation rules.
importProfileName: Indicates profile name created or updated to associate the relaxation rules during restore operation. “matchUrlString”: Indicates action URL string to match in archived relaxation rules.
replaceUrlString: Indicates string to replace in action URL while restoring relaxation rules.
overwrite: Existing rules action to purge existing relaxation rules and replace during import.
augment: Existing rules action to augment relaxation rules during import.
import appfw archive local: dutA_test_pr.tgz demo restore appfw profile dutA_test_pr
Export the archived file to the selected appliance by using the CLI
archive appfw profile <name> <archivename> [-comment <string>]
archive name: Indicates source for tar archive. This is a mandatory argument. name: Indicates the appfw profile name containing the relaxation rules to export
export appfw archive <name> <target>
> archive appfw profile test_pr archived_test_pr
> export appfw archive archived_test_pr local:dutA_test_pr
To export relaxation rules by using NetScaler GUI
-
Navigate to Security > NetScaler Web App Firewall.
-
In the details page, click NetScaler Web App Firewall Profiles link under Configuration Summary section.
-
In the NetScaler Web App Firewall Profile page, click the Relaxation Rules link under Advanced Settings section.
-
In the Relaxation Rules section, click Export All Relaxation Rules. The action applies to all security checks and on the ones which dynamic learning is enabled on that profile.Export-relaxation-rules
To import relaxation rules by using NetScaler GUI
-
Navigate to Security > NetScaler Web App Firewall.
-
In the details page, click the NetScaler Web App Firewall Profiles link under Configuration Summary section.
-
In the NetScaler Web App Firewall Profile page, click the Relaxation Rules link under Advanced Settings section.
-
In the Relaxation Rules section, click Import All Relaxation Rules.
-
In the Configure NetScaler Web App Firewall Profile page, set the following parameters:
-
Local file. Name of the compressed archived file containing the relaxation rules.
-
Profile Name. Name of the profile to which the relaxation rules are bound.
-
Matching URL String. Portion of the URL that matches.
-
Replace URL String. Portion of the URL that replaces the URL string.
-
Existing Rule Action. Select if the rule must overwrite existing rules or augment the existing rules.
-
-
Click OK.