Assets
Asset reference for WAF.
This page documents the following assets:
- Policy — Web Application Firewall (WAF) reverse-proxy instance: an Apache + ModSecurity (OWASP CRS) virtual host that fronts a tenant backend service and inspects incoming HTTP(S) requests to drop malicious traffic. Typically created first in detection mode (security_config.modsecurity.modsec_rule_engine=DetectionOnly, only logs violations), then switched to blocking mode (modsec_rule_engine=On) once verified.
- Waf — Web Application Firewall configuration
Policy
Web Application Firewall (WAF) reverse-proxy instance: an Apache + ModSecurity (OWASP CRS) virtual host that fronts a tenant backend service and inspects incoming HTTP(S) requests to drop malicious traffic. Typically created first in detection mode (security_config.modsecurity.modsec_rule_engine=DetectionOnly, only logs violations), then switched to blocking mode (modsec_rule_engine=On) once verified.
Schema
The following properties describe a Policy:
| Property | Type | Description |
|---|---|---|
listen_fqdn Required | string | Fully qualified domain name the WAF listens on (the public-facing VIP hostname). Examples: waf-myapp-acme.offnet.sbx.ginfra.net |
name RequiredForceNew | string | Name of the WAF instance, used as the MoldAPI job name and as the first DNS label of the listen FQDN (waf-<name>-<tenant>...). Must be alphanumeric with '-' or '_' separators, 1-40 characters. Immutable after creation. Examples: my-service |
security_config Required | object | Security-related configuration: OWASP Core Rule Set tuning, ModSecurity engine settings and custom rules. |
target_fqdn Required | string | Fully qualified domain name of the backend service the WAF reverse-proxies to. Examples: myapp.services.acme.sbx.eu.ginfra.net |
target_port Required | integer | TCP port of the backend service. Examples: 443 |
target_ssl | boolean | Whether the WAF connects to the backend over TLS. Defaults to true. Examples: true |
vhost_config Required | object | Apache virtual-host configuration for the reverse proxy. |
Examples
Waf
Web Application Firewall configuration
Schema
The following properties describe a Waf:
| Property | Type | Description |
|---|---|---|
listen_fqdn Required | string | Fully qualified domain name that the WAF listens on |
name Required | string | |
security_config Required | object | Security-related configurations |
target_fqdn Required | string | Fully qualified domain name targeted backend |
target_port Required | integer | Port on the target server |
target_ssl | boolean | Whether to use SSL for the connection to the target |
vhost_config Required | object | Virtual host configuration for the WAF |