You must update your signatures objects frequently to ensure that your Web App Firewall is providing protection against current threats. You must regularly update both the default Web App Firewall signatures and any signatures that you import from a supported vulnerability scanning tool.
NetScaler® regularly updates the default signatures for the Web App Firewall. You can update the default signatures manually or automatically. In either case, ask your NetScaler representative or NetScaler reseller for the URL to access the updates. You can enable automatic updates of the NetScaler native format signatures in the "Engine Settings" and "Signature Auto Update Settings" dialog boxes.
Most makers of vulnerability scanning tools regularly update the tools. Most websites also change frequently. You must update your tool and rescan your websites regularly, exporting the resulting signatures to a file and importing them into your Web App Firewall configuration.
When you update the Web App Firewall signatures from the NetScaler command line, you must first update the default signatures, and then issue more update commands to update each custom signatures file that is based on the default signatures. If you do not update the default signatures first, a version mismatch error prevents updating of the custom signatures files.
The following applies to merging a third-party signature object with a user-defined signature object with Native rules and user-added rules:
When a version 0 signatures is merged with a new imported file, the resultant signatures remain as version 0.
This means all native (or built-in) rules in the imported file will be ignored after the merge. This is to ensure that the version 0 signatures are maintained as is after a merge.
To include the native rules in the imported file for merge, you must update the existing signatures from version 0 first before the merge. This means you need to abandon the version 0 nature of the existing signatures.
When there is a NetScaler release upgrade, the file "default_signatures.xml" is added to the new build and the file "updated_signature.xml" is removed from the older build. After the upgrade, if the signature auto update feature is enabled, the appliance updates the existing signature to the latest version of the build and generates the "updated_signature.xml" file.