WAF recommendations
-
Get generated with the mentioned security checks
-
Not get generated with the mentioned security checks
-
WAF Profile
-
WAF Signature
Prerequisites
-
Must have the premium license.
-
Must be the load balancing virtual server.
Configure the WAF scan settings
-
Domain Name – Specify the publicly accessible/publicly reachable domain name that is associated with the application VIP. For example:
www.example.com.NoteStart URL, Login URL and Logout URL must match the specified domain. -
Traffic and Start URL – Provide the URL details of the application (server).
-
HTTP/HTTPS Protocol – Select the protocol of the application.
-
Traffic Timeout – The wait time (in seconds) for a single request during the scan. The value must be greater than 0.
-
Start URL – The home page of the application to initiate the scan. For example,
https://www.example.com/home. The URL must be a valid IPv4 address. If the IP addresses are private, then you must ensure that the private IP address is accessible from the NetScaler Console management IP.
-
-
Login URLs – Specify the login credentials, URLs, if any, to access the application.
-
Login URL – The URL to which the login data is sent for authentication. In HTML, this URL is commonly known as the action URL.
-
Authentication Method – Select the supported authentication method (form based or header based) for your application.
-
Form-based authentication requires submitting a form to the login URL with the login credentials. These credentials must be in the form of form fields and their values. The application then shares the session cookie that is used to maintain sessions during the scan.
-
Header-based authentication requires the Authentication header and its value in the headers section. The Authentication header must have a valid value and is used to maintain sessions during the scan. The form-fields should be left empty for Header-based.
-
-
Request Method – Select the HTTP method used when submitting form data to the login URL. The allowed request method is POST, GET, and PUT.
-
Form Fields – Specify the form data to be submitted to the login URL. Form Fields are required only if you select the form-based authentication. You must specify in the key-value pairs, where Field Name is the Key and Field Value is the Value. Ensure that all form fields needed for login to work are added correctly, including passwords. The values are encrypted before storing it in the database. You can click the Add button to add multiple form fields. For example, Field Name – user name and Field Value – admin.
-
HTTP Headers – The HTTP headers maybe required for the login to succeed. You must specify in the key-value pairs, where Header Name is the Key and Header Value is the Value. You can click the Add button to add multiple HTTP headers. One of the most common required HTTP headers is Content-Type header.

-
-
Logout URLs – Specify the URL that terminates the session after accessing. For example:
https://www.example.com/customer/logout.
-
Vulnerability – Select the vulnerabilities for the scanner to detect them. Currently, this is done for SQL Injection and Cross-site scripting violations. By default, all the violations are selected. After selecting the vulnerabilities, it simulates these attacks on the application to report the potential vulnerability. It is recommended to enable this detection that is not in the production environment. All other vulnerabilities are also reported, without simulating these attacks on the application.

-
Additional Settings
-
Requests Concurrency – The total requests sent to the web application in parallel.
-
Scan Depth - The depth of the web application up to which the scan must go on. For example, for a scan depth of value 2, the Start URL and all the links found in this URL are scanned. You must specify a value greater than or equal to 1.
-
Response size limit – The maximum limit on the response size. Any responses beyond the mentioned value are not scanned. The recommended limit is 3 MB (300000 bytes).
-
WAF scan recommendation process
-
Scans the provided web application through the provided URL.
-
Inspects the web application to discover the technologies used by the web application.
-
Simulates security attacks on the web application to detect potential vulnerabilities.
-
Recommends signatures based on the web technologies detected.
-
Recommends security checks based on vulnerabilities found and the analysis of the traffic.
-
Analyzes the web application responses to generate more granular settings.
-
Buffer Overflow
-
Field Formats
-
Credit Card
-
Cookie Consistency
-
HTML SQL Injection
-
HTML Cross Site Scripting
-
Form Field Consistency
-
CSRF Form Tagging
View scan report
-
WAF Recommendation – Enables you to view the summary of the total signatures and security checks recommended for the application.
-
Scan Detections – Enables you to view the collection of information such as technologies and violation details performed on the application. Click View Details to see the information about the detections and other details of the scan.

-
The configuration is applied on the NetScaler instance through the
appfw-import-objectStyleBook. -
The signatures file with recommendations configured is imported in the NetScaler instance.
-
The configuration is applied on the NetScaler instance through StyleBooks, depending upon the NetScaler version. For NetScaler 13.0,
waf-default-130StyleBook is used and for NetScaler 13.1,waf-default-131stylebook is used. -
The
Appfwprofile is created on your NetScaler and bound to the application using thepolicylabel. -
The signatures are bound to the appfw profile, if the recommended signatures are already applied.