Integrating NetScaler layer 3 with passive security devices (Intrusion Detection System)
-
Inspecting encrypted traffic. Most security devices bypass encrypted traffic, thereby leaving servers vulnerable to attacks. A NetScaler appliance can decrypt traffic and send it to IDS devices for enhancing the customer’s network security.
-
Offloading inline devices from TLS/SSL processing. TLS/SSL processing is expensive and it results in high system CPU in intrusion detection devices if they decrypt the traffic. As encrypted traffic is growing at a fast pace, these systems fail to decrypt and inspect encrypted traffic. NetScaler helps in offloading traffic to IDS devices from TLS/SSL processing. This way of offloading data results in an IDS device supporting a high volume of traffic inspection.
-
Loading balancing IDS devices. The NetScaler appliance load balances multiple IDS devices when there is a high volume of traffic by cloning traffic at the virtual server level.
-
Replicating traffic to passive devices. The traffic flowing into the appliance can be replicated to other passive devices for generating compliance reports. For example, few government agencies mandate every transaction to be logged in some passive devices.
-
Fanning traffic to multiple passive devices. Some customers prefer to fan out or replicate incoming traffic into multiple passive devices.
-
Smart selection of traffic. Every packet flowing into the appliance might not be must be content inspected, for example download of text files. User can configure the NetScaler appliance to select specific traffic (for example .exe files) for inspection and send the traffic to IDS devices for processing data.
How NetScaler is integrated with IDS device with L3 connectivity
-
A client sends an HTTP/HTTPS request to the NetScaler appliance.
-
The appliance intercepts the traffic and sends the data to remote IDS devices across different data centers or even in a cloud. This integration is done through IP tunneled layer 3. For more information about IP tunneling in a NetScaler appliance, see IP tunnels topic.
-
If the traffic is an encrypted one, the appliance decrypts the data and sends it as a plain text.
-
Based on policy evaluation, the appliance applies a “MIRROR” type content inspection action.
-
The action has an IDS service or load balancing service (for multiple IDS device integrations) configured in it.
-
The IDS device is configured as content inspection service type “Any” on the appliance. The content inspection service is then associated to the content inspection profile of type “MIRROR” and the tunnel parameter which specifies the IP tunneled layer 3 interface through which the data is forwarded to the IDS device.
-
Similarly, when the back-end server sends a response to the NetScaler, the appliance replicates the data and forwards it to the IDS device.
-
If your appliance is integrated to one or more IDS devices and if you prefer to load balance the devices, then you can use the load balancing virtual server.
Software licensing
-
ADC Premium
-
ADC Advanced
Configuring intrusion detection system integration
Scenario 1: Integration with a single IDS device
-
Enable content inspection
-
Add content inspection profile of type MIRROR for service representing IDS device.
-
Add IDS service of type “ANY”
-
Add content inspection action of type “MIRROR”
-
Add content inspection policy for IDS inspection
-
Bind content inspection policy to content switching or load balancing virtual service of type HTTP/SSL
Enable Content Inspection
enable ns feature contentInspection LoadBalancing
Add Content Inspection profile of type “MIRROR"
add contentInspection profile <name> -type MIRROR -ipTunnel <iptunnel_name>
add contentInspection profile IDS_profile1 -type MIRROR –ipTunnel ipsect-tunnel1
Add IDS service
add service <Service_name> <IP> ANY <Port> - contentinspectionProfileName <Name> -healthMonitor OFF -usip ON –useproxyport OFF
add service IDS_service 1.1.1.1 ANY 8080 -contentInspectionProfileName IDS_profile1 -healthMonitor OFF
Add content inspection action of type MIRROR for IDS service
add ContentInspection action < action_name > -type MIRROR -serverName Service_name/Vserver_name>
add ContentInspection action IDS_action -type MIRROR –serverName IDS_service
Add content inspection policy for IDS inspection
add contentInspection policy < policy_name > –rule <Rule> -action <action_name>
add contentInspection policy IDS_pol1 –rule true –action IDS_action
Bind content inspection policy to content switching or load balancing virtual service of type HTTP/SSL
add lb vserver <name> <vserver name>
add lb vserver HTTP_vserver HTTP 1.1.1.3 8080
Bind Content Inspection policy to content switching virtual server or load balancing virtual server of type HTTP/SSL
bind lb vserver <vserver name> -policyName < policy_name > -priority < priority > -type <REQUEST>
bind lb vserver HTTP_vserver -policyName IDS_pol1 -priority 100 -type REQUEST
Scenario 2: Load balancing multiple IDS devices
-
Add content inspection profile 1 of type MIRROR for IDS service 1
-
Add content inspection profile 2 of type MIRROR for IDS service 2
-
Add IDS service 1 of type ANY for IDS device 1
-
Add IDS service 2 of type ANY for IDS device 2
-
Add load balancing virtual server of type ANY
-
Bind IDS service 1 to load balancing virtual server
-
Bind IDS service 2 to load balancing virtual server
-
Add content inspection action for the load balancing of IDS devices.
-
Add content inspection policy for inspection
-
Add content switching or load balancing virtual server of type HTTP/SSL
-
Bind content inspection policy to load balancing virtual server of type HTTP/SSL
Add content inspection profile1 of type MIRROR for IDS service 1
add contentInspection profile <name> -type ANY – ipTunnel <iptunnel_name>
add contentInspection profile IDS_profile1 -type MIRROR - ipTunnel ipsect_tunnel1
Add content inspection profile 2 for type MIRROR for IDS service 2
add contentInspection profile <name> -type ANY – ipTunnel <iptunnel_name>
add contentInspection profile IDS_profile2 -type ANY – ipTunnel ipsect_tunnel2
Add IDS service 1 of type ANY for IDS device 1
add service <Service_name_1> <Pvt_IP1> ANY <Port> -contentInspectionProfileName <IDS_Profile_1> –usip ON –useproxyport OFF
add service IDS_service1 1.1.1.1 ANY 80 -contentInspectionProfileName IDS_profile1 -usip ON -useproxyport OFF
Add IDS service 2 of type ANY for IDS device 2
add service <Service_name_1> <Pvt_IP1> ANY -contentInspectionProfileName <Inline_Profile_2> -healthmonitor OFF –usip ON –useproxyport OFF
add service IDS_service 1 1.1.2 ANY 80 -contentInspectionProfileName IDS_profile2
Add load balancing virtual server
add lb vserver <vserver_name> ANY <Pvt_IP3> <port>
add lb vserver lb-IDS_vserver ANY 1.1.1.2
Bind IDS service 1 to load balancing virtual server
bind lb vserver <Vserver_name> <Service_name_1>
bind lb vserver lb-IDS_vserver IDS_service1
Bind IDS service 2 to load balancing virtual server
bind lb vserver <Vserver_name> <Service_name_1>
bind lb vserver lb-IDS_vserver IDS_service2
Add content inspection action for the IDS service
add contentInspection action <name> -type <type> (-serverName <string> [-ifserverdown <ifserverdown>]
add ContentInspection action IDS_action -type MIRROR –serverName lb-IDS_vserver
Add content inspection policy for inspection
add contentInspection policy <policy_name> –rule <Rule> -action <action_name>
add contentInspection policy IDS_pol1 –rule true –action IDS_action
Add content switching or load balancing virtual server of type HTTP/SSL
add lb vserver <name> <vserver name>
add lb vserver http_vserver HTTP 1.1.1.1 8080
Bind Content Inspection policy to load balancing virtual server of type HTTP/SSL
bind lb vserver <vserver name> -policyName < policy_name > -priority <> -type <REQUEST>
bind lb vserver http_vserver -policyName IDS_pol1 -priority 100 -type REQUEST
Configure inline service integration using the NetScaler GUI
-
Navigate to Security > Content Inspection > ContentInspection Profiles.
-
In the ContentInspection Profile page, click Add.
-
In the Create ContentInspectionProfile page, set the following parameters.
-
Profile Name. Name of the content inspection profile for IDS.
-
Type. Select the profile types as MIRROR.
-
Connectivity. Layer 2 or Layer 3 interface.
-
IP Tunnel. Select the network communication channel between the two networks.
-
-
Click Create.
-
Navigate to Traffic Management > Load Balancing > Services and click Add.
-
In the Load Balancing Service page, enter the content inspection service details.
-
In the Advanced Settings section, click Profiles.
-
Go to the Profiles section and click the Pencil icon to add the content inspection profile.
-
Click OK.
-
Navigate to Load Balancing > Servers. Add a virtual server of type HTTP or SSL.
-
After entering the server details, click OK and again OK.
-
In the Advanced Settings section, click Policies.
-
Go the Policies section and click the Pencil icon to configure the content inspection policy.
-
On the Choose Policy page, select Content Inspection. Click Continue.
-
In the Policy Binding section, click “+” to add a Content Inspection policy.
-
In the Create CI Policy page, enter a name for the Inline content inspection policy.
-
In the Action field, click the “+” sign to create an IDS content inspection action of type MIRROR.
-
In the Create CI Action page, set the following parameters.
-
Name. Name of the content inspection Inline policy.
-
Type. Select the type as MIRROR.
-
Server Name. Select the server/service name as Inline devices.
-
If Server Down. Select an operation if the server goes down.
-
Request Time-out. Select a time-out value. Default values can be used.
-
Request Time-out Action. Select a time-out action. Default values can be used.
-
-
Click Create.
-
In the Create CI Policy page, enter other details.
-
Click OK and Close.