Search Imperva Community for
We are running Imperva WAF X2010 which is one physical appliance, and I have been tasked with installing patches on our Imperva WAF X2010.
I have been told that if the Imperva WAF is running some modes, there will be no impact on traffic flow during a patch installation/software upgrade. Is that true? And what modes/settings would allow this to happen?
How about the impact on traffic flow in case of a reboot? Or even when the WAF is powered off?
One more question, the WAF's Software Update screen shows as follows. Does it mean I need to install patches twice, one for MX, and another for Gateway, though they are in on physical appliance?
Component type: MXCurrently installed: v126.96.36.199Target version: v188.8.131.52 (SecureSphereV11.5.0-x86_64-Patch95_0.x)
Component type: GatewayCurrently installed: v184.108.40.206Target version: v220.127.116.11 (SecureSphereV11.5.0-x86_64-Patch95_0.x)
Any advice would be appreciated.
Hi Stefan, and Anderson,
Thank you very much for your prompt reply.
We target to upgrade to at least v13 which will fix several vulnerabilities detected by Nessus.
As far as I understand your advice, generally speaking:
There shall be no service impact during running the patch as following example:>>> "Run the patch by typing ./[patch filename]For example: ./SecureSphereV11.5-x86_64-Patch1_0.x"
A graceful reboot would inevitably cause traffic to be temporarily interrupted because "because the OS has to process the orderly shutdown of the kernel processes and the network interfaces. It then has to bring up the network interfaces, auto-negotiate speed and duplex">>>"Reboot the machine only after receiving the message that the patch has been successfully installed."
To minimise potential impact, I have to configure the GW to fail-open the bridge connection because "If the gateway is in fail-open mode (bypass mode), during upgrade, traffic will be down only for up to 10 seconds while the gateway is being rebooted once time at the end of the upgrade."
I observe that we are working in IMPVHA Bride mode as what is shown in Main>Setup>Gateways>Filter>By Mode
STP BrideGatewayNo data foundIMPVGA BrideGateway Status Active .. .. Model Appliance TypeERBWAF01 Running Yes .. .. X2010 Physical
SniffingGatewayNo data found
Reverse Proxy (Apache)GatewayNo data found
Reverse Proxy KernelGatewayNo data found
With reference to the Admin Guide, under the Gateway Groups section, I tried in vain to configure the GW to fail-open the bridge connection because there is no option for me to select a fail mode as the attachment shows. Could you advise too? Thanks again.
or Contact Us
Copyright @ 2019 Imperva. All rights reserved