Manual configuration By using the command line interface
To create a profile by using the command line interface
-
add appfw profile <name> [-defaults ( basic | advanced )] -
set appfw profile <name> -type ( HTML | XML | HTML XML ) -
save ns config
Example
add appfw profile pr-basic -defaults basic
set appfw profile pr-basic -type HTML
save ns config
To configure a profile by using the command line interface
-
set appfw profile <name> <arg1> [<arg2> ...]where<arg1>represents a parameter and<arg2>represents either another parameter or the value to assign to the parameter represented by<arg1>. For descriptions of the parameters to use when configuring specific security checks, see Advanced Protections and its subtopics. For descriptions of the other parameters, see "Parameters for Creating a Profile." -
save ns config
Example
set appfw profile -startURLAction log stats
set appfw profile -denyURLAction block log stats
set appfw profile -cookieConsistencyAction log stats
set appfw profile -crossSiteScriptingAction log stats
set appfw profile -crossSiteScriptingTransformUnsafeHTML ON
set appfw profile -fieldConsistencyAction log stats
set appfw profile -SQLInjectionAction log stats
set appfw profile -SQLInjectionTransformSpecialChars ON
set appfw profile -SQLInjectionOnlyCheckFieldsWithSQLChars ON
set appfw profile -SQLInjectionParseComments checkall
set appfw profile -fieldFormatAction log stats
set appfw profile -bufferOverflowAction block log stats
set appfw profile -CSRFtagAction log stats
save ns config
To create and configure a policy
-
add appfw policy <name> <rule> <profile> -
save ns config
Example
add appfw policy pl-blog "HTTP.REQ.HOSTNAME.DOMAIN.EQ("blog.example.com")" pr-blog
To bind a Web App Firewall policy
-
bind appfw global <policyName> <priority> -
save ns config
Example
bind appfw global pl-blog 10
save ns config
To configure session limit per PE
-
set appfw settings <session limit>
Example
> set appfw settings -sessionLimit 500000`
Done
Default value:100000 Max value:500000 per PE