WAF Insight
How WAF insight works
-
Threat index. A single-digit rating system that indicates the criticality of attacks on the application, regardless of whether the application is protected by a NetScaler appliance. The more critical the attacks on an application, the higher the threat index for that application. Values range from 1 through 7.The threat index is based on attack information. The attack-related information, such as violation type, attack category, location, and client details, gives you insight into the attacks on the application. Violation information is sent to NetScaler Console only when a violation or attack occurs. Many breaches and vulnerabilities lead to a high threat index value.
-
Safety index. A single-digit rating system that indicates how securely you have configured the NetScaler instances to protect applications from external threats and vulnerabilities. The lower the security risks for an application, the higher the safety index. Values range from 1 through 7.The safety index considers both the application firewall configuration and the NetScaler system security configuration. For a high safety index value, both configurations must be strong. For example, if rigorous application firewall checks are in place but NetScaler system security measures, such as a strong password for the
nsrootuser, have not been adopted, applications are assigned a low safety index value. -
Actionable information. The information that you need for lowering the threat index and increasing the safety index, which significantly improves application security. For example, you can review information about violations, existing and missing security configurations for application firewall and other security features, the rate at which the applications are being attacked.
Configure WAF insight
-
Navigate to Infrastructure > Instances > NetScaler and select the instance type. For example, VPX.
-
Select the instance and from the Select Action list, select Configure Analytics.
-
On the Configure Analytics on virtual server window:
-
Select the virtual servers that you want to enable security insight and click Enable Security & Analytics.The Enable Security & Analytics window is displayed.
-
Select WAF Security Violations
-
Under Advanced Options, select Logstream or IPFIX as Transport ModeNoteFor NetScaler 12.0 or earlier, IPFIX is the default option for Transport Mode. For NetScaler 12.0 or later, you can either select Logstream or IPFIX as Transport Mode.For more information about IPFIX and Logstream, see Logstream overview.
-
The Expression is true by default
-
Click OK
Note-
If you are not on the Flexed license and you select virtual servers that are not licensed, then NetScaler Console first licenses those virtual servers and then enables analytics.
-
-
Configure geo locations for security insight reports
-
Copy the Geo Database file, Citrix_Netscaler_InBuilt_GeoIP_DB.csv, to any location on the NetScaler appliance.
-
Open the Geo Database file with a text editor, such as vi editor, and add an entry for every location in your organization.The entry must be in the following format:
<start IP\>,<end IP\>,,<country\>,<state\>,,<city\>,,longitude,latitudeFor example,4.17.142.224,4.17.142.239,,US,New York,,Harrison,,73.7304,41.0568 -
Run the following commands to enable geo-location logging and logging in the CEF format:
-
add locationFile <Complete path with DB file\>
-
set appfw settings -geoLocationLogging ON
-
set appfw settings -CEFLogging ON
-
Monitor IP reputation
| IP Reputation score | Level of Risk |
|---|---|
| 1–20 | High Risk |
| 21–40 | Suspicious |
| 41–60 | Moderate Risk |
| 61–80 | Low Risk |
| 81–100 | Trustworthy |
-
Navigate to Security > Security Violations, and under WAF, select the application you want to monitor.
-
The Threat Index and Safety Index scores are displayed. Click View Details.
-
Under Application Firewall Configuration, you can view the IP reputation safety index score.
Thresholds
-
Navigate to Settings > Analytics Settings > Thresholds, and select Add.
-
Select the traffic type as Security in the Traffic Type field, and enter required information in the other appropriate fields such as Name, Duration, and entity.
-
In the Rule section, use the Metric, Comparator, and Value fields to set a threshold.For example, "Threat Index" ">" "5"
-
Click Create.
WAF insight use cases
Obtain an overview of the threat environment
Determine the existing and missing security configuration for an application
-
Application Firewall Configuration. Shows how many signature and security entities are not configured.
-
NetScaler Console System Security. Shows how many system security settings are not configured.

Identify applications that require immediate attention
Determine the number of attacks in a given time
-
Attack time
-
IP address of the client from which the attack happened
-
Severity
-
Category of violation
-
URL from which the attack originated, and other details.