Unified Security dashboard
-
If you are a new user or if you have not configured any protections either through StyleBooks or directly on NetScaler® instances, the following page appears after you click Security > Security Dashboard.
-
You can view the total number of virtual servers that require protection. Click Get Started to view details in Unsecured Applications.
-
The eligible virtual server types for configuring protections are load balancing and content switching.
Secured applications
Configure protections for unsecured applications
-
WAF Recommendation scanner - This option enables you to run a scan on your application. Based on certain parameters of the scan, the result suggests you the protections for your application. You might consider applying those recommendations.
-
Select & Customize Protections - This option enables you to choose from different template options or customize your protections and deploy.
-
OWASP Top 10 - A predefined template that has the industry-standard protections against the OWASP top-10 security risks. For more information, see
https://owasp.org/www-project-top-ten/. -
CVE Protections - You can create the signature set from the list of pre-configured signature rules classified under known vulnerability categories. You can select signatures to configure log or block action when a signature pattern matches the incoming traffic. The log message contains the vulnerability details.
-
Custom Protections - Select the protections and deploy them based on your requirements.
-
-
Choose existing protections - This option clones the protections that are deployed in an existing application. If you want to deploy those same protections to another application, you can select this option and deploy it to another application as it is. You can also select this option as a template, modify the protections, and then deploy.
WAF recommendation scanner
-
You can run only one scan at a time for an application. To start a new scan for the same application or a different application, you must wait until the previous scan gets completed.
-
You can click View History to view the history and status of the past scans. You can also click View Report and then apply recommendations later.
-
The NetScaler instance must be 13.0 41.28 or later (for security checks) and 13.0 or later (for signatures).
-
Must have the premium license.
-
Must be the load balancing virtual server.
-
Under Scan Parameters:
-
Domain Name – Specify a valid accessible IP address or the publicly reachable domain name that is associated with the application. For example:
www.example.com. -
HTTP/HTTPS Protocol – Select the protocol of the application.
-
Traffic Timeout – The wait time (in seconds) for a single request during the scan. The value must be greater than 0.
-
URL to start scan from – The home page of the application to initiate the scan. For example,
https://www.example.com/home. The URL must be a valid IPv4 address. If the IP addresses are private, then you must ensure that the private IP address is accessible from the NetScaler Console on-prem management IP. -
Login URL – The URL to which the login data is sent for authentication. In HTML, this URL is commonly known as the action URL.
-
Authentication Method – Select the supported authentication method (form based or header based) for your application.
-
Form-based authentication requires submitting a form to the login URL with the login credentials. These credentials must be in the form of form fields and their values. The application then shares the session cookie that is used to maintain sessions during the scan.
-
Header-based authentication requires the Authentication header and its value in the headers section. The Authentication header must have a valid value and is used to maintain sessions during the scan. The form-fields should be left empty for Header-based.
-
-
Request Method – Select the HTTP method used when submitting form data to the login URL. The allowed request method is POST, GET, and PUT.
-
Form Fields – Specify the form data to be submitted to the login URL. Form Fields are required only if you select the form-based authentication. You must specify in the key-value pairs, where Field Name is the Key and Field Value is the Value. Ensure that all form fields needed for login to work are added correctly, including passwords. The values are encrypted before storing it in the database. You can click Add to add multiple form fields. For example, Field Name – user name and Field Value – admin.
-
Logout URL – Specify the URL that terminates the session after accessing. For example:
https://www.example.com/customer/logout.
-
-
Under Scan Configurations:
-
Vulnerabilities to check – Select the vulnerabilities for the scanner to detect them. Currently, this is done for SQL Injection and Cross-site scripting violations. By default, all the violations are selected. After selecting the vulnerabilities, it simulates these attacks on the application to report the potential vulnerability. It is recommended to enable this detection that is not in the production environment. All other vulnerabilities are also reported, without simulating these attacks on the application.
-
Response size limit – The maximum limit on the response size. Any responses beyond the mentioned value are not scanned. The recommended limit is 10 MB (1000000 bytes).
-
Requests Concurrency – The total requests sent to the web application in parallel.
-
-
The WAF scan settings configuration is complete. You can click Start Scan to begin the scanning process and wait for the progress to complete. After the scan is complete, click View Report.

-
In the scan results page, click Review Recommendation.

-
Review the protections or edit/add any other protections, and click Deploy.
When you apply security checks successfully:
-
The configuration is applied on the NetScaler instance through StyleBooks, depending upon the version.
-
For NetScaler 13.0,
unified-appsec-protection-130StyleBook is used. -
For NetScaler 13.1,
unified-appsec-protection-131StyleBook is used. -
For NetScaler 14.1,
unified-appsec-protection-141StyleBook is used.
-
-
The
Appfwprofile is created on your NetScaler and bound to the application using thepolicylabel. -
The signatures are bound to the appfw profile, if the recommended signatures are already applied.
Export the WAF scanner report
-
Navigate to Security > Dashboard > Manage Applications.
-
In the Unsecured Applications tab, click View History.
-
On the Scan History page, select the desired scan and click View Report.
-
On the Scan Results page, click the Export icon.
-
On the Exports Now page, choose the export type.
-
Select an export file format: PDF, JPG, or PNG
-
Enter a title for the report.
-
Click Export.
-
Select the CSV file format.
-
Select the number of data records to export from the list.
-
Enter a title for the report.
-
Click Export.
Select and customize protections
OWASP Top 10
-
Pattern. Logs only violation pattern.
-
Pattern payload. Logs violation pattern and 150 bytes of extra JSON payload.
-
Pattern, payload, header. Logs violation pattern, 150 bytes of extra JSON payload and HTTP header information.
CVE protections
Custom Protection
Choose existing protections
