Global InfraGlobal Infra Cloud

Assets

Asset reference for WAF.

Edit

This page documents the following assets:

  • Policy — Web Application Firewall (WAF) reverse-proxy instance: an Apache + ModSecurity (OWASP CRS) virtual host that fronts a tenant backend service and inspects incoming HTTP(S) requests to drop malicious traffic. Typically created first in detection mode (security_config.modsecurity.modsec_rule_engine=DetectionOnly, only logs violations), then switched to blocking mode (modsec_rule_engine=On) once verified.
  • Waf — Web Application Firewall configuration

Policy

Web Application Firewall (WAF) reverse-proxy instance: an Apache + ModSecurity (OWASP CRS) virtual host that fronts a tenant backend service and inspects incoming HTTP(S) requests to drop malicious traffic. Typically created first in detection mode (security_config.modsecurity.modsec_rule_engine=DetectionOnly, only logs violations), then switched to blocking mode (modsec_rule_engine=On) once verified.

Schema

The following properties describe a Policy:

PropertyTypeDescription
listen_fqdn
Required
stringFully qualified domain name the WAF listens on (the public-facing VIP hostname).
Examples:waf-myapp-acme.offnet.sbx.ginfra.net
name
RequiredForceNew
stringName of the WAF instance, used as the MoldAPI job name and as the first DNS label of the listen FQDN (waf-<name>-<tenant>...). Must be alphanumeric with '-' or '_' separators, 1-40 characters. Immutable after creation.
Examples:my-service
security_config
Required
objectSecurity-related configuration: OWASP Core Rule Set tuning, ModSecurity engine settings and custom rules.
target_fqdn
Required
stringFully qualified domain name of the backend service the WAF reverse-proxies to.
Examples:myapp.services.acme.sbx.eu.ginfra.net
target_port
Required
integerTCP port of the backend service.
Examples:443
target_ssl
booleanWhether the WAF connects to the backend over TLS. Defaults to true.
Examples:true
vhost_config
Required
objectApache virtual-host configuration for the reverse proxy.

Examples


Waf

Web Application Firewall configuration

Schema

The following properties describe a Waf:

PropertyTypeDescription
listen_fqdn
Required
stringFully qualified domain name that the WAF listens on
name
Required
string
security_config
Required
objectSecurity-related configurations
target_fqdn
Required
stringFully qualified domain name targeted backend
target_port
Required
integerPort on the target server
target_ssl
booleanWhether to use SSL for the connection to the target
vhost_config
Required
objectVirtual host configuration for the WAF

Examples

On this page