NetScaler® Web App Firewall security recommendations
-
For RFC compliance checks, it is recommended to keep 'APPFW_RFC_BLOCK' as the default
rfcprofilefor the WAF profile. -
WAF supports inserting
Samesitecookie attribute value and the cookie can be restricted to the same-site or cross-site context by selecting 'Strict' or 'Lax' values.
Deploy NetScaler in the two-arm mode
Use a 'Default Deny' policy
add appfw profile default_deny_profile -defaults advanced
add appfw policy default_deny_policy true default_deny_profile
bind appfw global default_deny_policy <PRIORITY>
set appfw settings -defaultProfile appfw_block
NetScaler Web App Firewall – Building multiple tiers of security
set appfw settings -sessionCookieName "citrix_ns_id_1"
First tier of security
-
Enable Buffer Overflow, SQL injection, and Cross Site scripting.
-
A start URL is needed when the application is particular on which URLs must be accessed and have to protect against forceful browsing.
-
Enable Field Format Checks if your application is expecting inputs in a form field.
Second tier of security
Third tier of security
-
Based on the application needs, enable Advanced Profile Security checks like CSRF tagging, Cookie Consistency, Form Field consistency on parts of applications that need it.
-
Advanced security checks require more processing and can affect the performance. Unless your application needs advanced security, you might want to start with a basic profile and tighten the security as required for your application.
-
Enable Form Field Consistency check: This check is required to verify if the web forms were not modified inappropriately by the client. An application that serves and hosts critical information in forms needs the check.
-
CSRF Form tagging check: This check is for forms. The Cross Site Request Forgery (CSRF) Form Tagging check tags each web form sent by a protected website to users with a unique and unpredictable FormID, and then examines the web forms returned by users to ensure that the supplied FormID is correct. This check protects against cross-site request forgery attacks. This check must be enabled if the application has web-based forms. This check requires relatively little CPU processing capacity compared to certain other security checks that analyze web forms in depth. It is therefore able to handle high volume attacks without seriously degrading the performance of the protected website or the NetScaler Web App Firewall itself.
NetScaler Web App Firewall workflow steps
-
Configure the security profile.
-
Apply signatures for all known threats - the negative model.
-
Configure traffic policies that can detect the correct traffic flow where this security profile must be activated.
-
Configure the learning infrastructure.
-
Deploy the learned rules for protection.
-
Validate the learning data along with the signatures applied before going live.