Forum Discussion
Testing a WAF policy
Hi Ashis_K_Patra ,
It depends on each application.
But it's good to start your AWAF policy by ( Rapid deployment with transparent mode ) and define your server technologies well.
and start your way to fine tune your policy depending on learning.
there is no standard way to implement your policy it depends on what are you going to achieve from this AWAF policy for EX >> you want to use ( Positive security module or negative security module )
you need to restrict parameters , file types , URIs , you want to configure Cookies protections or not and stuff like this.
you have to narrow your options to start from it , AWAF has a huge features , you have to define your needs from AWAF policy first.
About testing >>> you can use the policy in test environment to simulate your application , then enforce your policy into blocking mode and test all features that you configured. such as try to perform and attack script and see if the AWAF policy blocked it or there is missing configs needed , check a disallowed url and see if AWAF blockes your or still need further configuration , and stuff like this.
Thanks Mohamed_Ahmed_Kansoh ,
I will be using in
- Rapid Deployment mode without any modification.
- Keeping it as Transparent.
- And put the Signatures in Staging stage.
Later on we will analyse the logs and then we will decide on the modification, part. And then we can apply the policy in Negative Security Model.
So, regaridng the testing, I dont have a test environment, however I have UAT Applications hosted in my Prod enviroment and I will be testing in those apps first and based on the result I will implemnet in the Prod app.
So, I need your help in testing some scenarios, if there are any tools (kindly share link). and what could be the testing scenarios in a prod enviroment.
This part is new to me and learning to implement with some test scenarios. Please guide me 🙂
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com