Web application firewall StyleBook 编辑
Web application firewall StyleBook
Citrix Web App Firewall is a web application firewall (WAF) that protects web applications and sites from both known and unknown attacks, including all application-layer and zero-day threats.
Citrix ADM now provides a default StyleBook with which you can more conveniently create an application firewall configuration on Citrix ADC instances.
Deploying application firewall configurations
The following task assists you in deploying a load balancing configuration along with the application firewall and IP reputation policy on Citrix ADC instances in your business network.
To create an LB configuration with application firewall settings:
In Citrix ADM, navigate to Applications > Configurations > StyleBooks. The StyleBooks page displays all the StyleBooks available for your use in Citrix ADM. Scroll down and find HTTP/SSL Load Balancing StyleBook with application firewall policy and IP reputation policy. You can also search for the StyleBook by typing the name as
lb-appfw
. Click Create Configuration.The StyleBook opens as a user interface page on which you can enter the values for all the parameters defined in this StyleBook.
Enter values for the following parameters:
Load Balanced Application Name. Name of the load balanced configuration with application firewall to deploy in your network.
Load balanced App Virtual IP address. Virtual IP address at which the Citrix ADC instance receives client requests.
Load Balanced App Virtual Port. The TCP Port to be used by the users in accessing the load balanced application.
Load Balanced App Protocol. Select the front-end protocol from the list.
Application Server Protocol. Select the protocol of the application server.
As an option, you can enable and configure the Advanced Load Balancer Settings.
Optionally, you can also set up an authentication server for authenticating traffic for the load balancing virtual server.
Click “+” in the server IPs and Ports section to create application servers and the ports that they can be accessed on.
You can also create FQDN names for application servers.
You can also specify the details of the SSL certificate.
You can also create monitors in the target Citrix ADC instance.
To configure an application firewall on the virtual server, enable WAF Settings.
Ensure that the application firewall policy rule is true if you want to apply the application firewall settings to all traffic on that VIP. Otherwise, specify the Citrix ADC policy rule to select a subset of requests to which to apply the application firewall settings. Next, select the type of profile that has to be applied - HTML or XML.
Optionally you can configure detailed application firewall profile settings by enabling the application firewall Profile Settings check box.
Optionally, if you want to configure application firewall signatures, enter the name of the signature object that is created on the Citrix ADC instance where the virtual server is to be deployed.
Note
You cannot create a signature object by using this StyleBook.
Next, you can also configure any other application firewall profile settings such as, StartURL settings, DenyURL settings and others.
For more information on application firewall and configuration settings, see Application Firewall.
In the Target Instances section, select the Citrix ADC instance on which to deploy the load balancing virtual server with the application firewall.
Note
You can also click the refresh icon to add recently discovered Citrix ADC instances in Citrix ADM to the available list of instances in this window.
You can also enable IP Reputation check to identify the IP address that is sending unwanted requests. You can use the IP reputation list to preemptively reject requests that are coming from the IP with the bad reputation.
Click Create to create the configuration on the selected Citrix ADC instances.
Tip
Citrix recommends that you select Dry Run to check the configuration objects that must be created on the target instance before you run the actual configuration on the instance.
When the configuration is successfully created, the StyleBook creates the required load balancing virtual server, application server, services, service groups, application firewall labels, application firewall policies, and binds them to the load balancing virtual server.
The following figure shows the objects created in each server:
To see the ConfigPack created on Citrix ADM, navigate to Applications > Configurations.
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论