Signature auto update
Customizable location
Update signatures
Configure the signature auto update
set appfw settings SignatureAutoUpdate on
set appfw settings SignatureUrl https://s3.amazonaws.com/NSAppFwSignatures/SignaturesMapping.xml
-
Navigate to Security > NetScaler Web App Firewall > Signatures.
-
Select Auto Update Settings from Action.
-
Enable the Signatures Auto Update option.
-
You can specify a customized path for the signature update URL, if necessary. Click Reset to reset to the default
s3.amazonaws.com server. -
Click OK.
Update signatures manually
update appfw signatures "*Default Signatures"
update appfw signatures cenzic –mergedefault
Default Signatures Is case sensitive. Cenzic in the preceding command is the name of the signature file that is updated.
Import default signatures without internet access
-
Create a local directory such as
<MySignatures>on a local server. -
Open the AWS site.
-
Copy the
SignaturesMapping.xmlfile to the<MySignatures>folder.
SignaturesMapping.xml file, you can see all the xml files for signatures and their corresponding sha1 files for different supported versions. One such pair is highlighted in the following screenshot:
-
Create a subdirectory
<sigs>in the<MySignatures>folder. -
Copy all pairs of the
*.xml files listed in the <file>tags and the*.xml.sha1files listed in the corresponding<sha1>tags of theSignaturesMapping.xmlfile to the<sigs>folder. The following are a few sample files that is copied to the<sigs>folder:
https://s3.amazonaws.com/NSAppFwSignatures/sigs/sig-r10.1b86v3s3.xml https://s3.amazonaws.com/NSAppFwSignatures/sigs/sig-r10.1b86v3s3.xml.sha1 https://s3.amazonaws.com/NSAppFwSignatures/sigs/sig-r10.1b0v3s2.xml https://s3.amazonaws.com/NSAppFwSignatures/sigs/sig-r10.1b0v3s2.xml.sha1
<MySignatures> folder and it can be in any location but the subdirectory <sigs> must be a subdirectory in the <MySignatures> folder where the mapping file is copied. In addition, ensure that as shown in the SignaturesMapping.xml, the subdirectory name <sigs> must have the exact name and is case sensitive. All Signature files and their corresponding sha1 files should be copied under this <sigs> directory.
set appfw settings SignatureUrl https://myserver.example.net/MySignatures/SignaturesMapping.xml
-
Add the url
https://myserver.example.netto/netscaler/ns_gui/admin_ui/php/application/controllers/utils.phpso that Content Security Policy (CSP) security does not block the url access. Please note that these settings do not persists in an upgrade. User has to add it again after the upgrade.
$configuration_view_connect_src = "connect-src 'self' https://app.pendo.io https://s3.amazonaws.com https://myserver.example.net;";
-
User must configure the webserver
https://myserver.example.netsuch that it responds to the following CORS headers forhttps://myserver.example.net/MySignatures/SignaturesMapping.xml
Access-Control-Allow-Methods: GET
Access-Control-Allow-Origin: *
Access-Control-Max-Age: 3000
Guidelines to update signatures
-
The signatures are updated when the Signature update URL has a signature object which has the same or newer version.
-
Each Signature Rule is associated with a rule ID and version number. For example:
<SignatureRule id="803" version="16" …> -
Signature Rule from the incoming Signatures file with the same ID and version number as the existing one is ignored even if it has different patterns or log string.
-
Signature Rule with a new ID is added. All the actions and enabled flag are used from the new file.Note:You must review the updated signatures periodically to enable the newly added rules and change other action settings as per the requirements of the application.
-
Rules with the same ID but with a newer version number replace the existing one. All the actions and enabled flag from the existing rule is preserved.
Auto-enable new signatures
Auto-enable new signatures using the GUI
-
Navigate to Security > NetScaler Web App Firewall > Signatures.
-
Select a signature and click Edit.
-
Select Auto Enable New Signatures.Auto-enable new WAF signature default rules
Auto-enable new signatures using the CLI
import appfw signatures <src> <name> [-xslt <string>] [-comment <string>] [-overwrite] [-merge [-preservedefactions]] [-sha1 <string>] [-VendorType Snort] [-autoEnableNewSignatures ( ON | OFF )]
import signatures http://www.example.com/ns/signatures.xml my-signature -autoEnableNewSignatures ON