Imperva Cyber Community

communities_1.jpg
 View Only
  • 1.  LAB Testing in VM environment of WAF

    Posted 06-14-2023 03:09

    Hello all,

    I am doing WAF testing on the VM environment.I need information regarding how can i do PoC in Waf in our VM LAB environment.

    1)How can i create an web application so that we can test any vulnerable URL we can access from outside and how the WAF device will protect.

    What would be the traffic Flow for my LAB environment?

    2)Which mode I will be used in my WAF device is it 'Bridge IMPVHA or Reverse proxy mode? Can anyone explain in easy method of the bridge mode and Reverse proxy mode working.

    3)As of now, i have created a Management server (VM150) and single gateway model (V2500) and both are running and registered.

    Waiting for your response.

    Regards,

    Sagar


    #On-PremisesWAF(formerlySecuresphere)

    ------------------------------
    Sagar E
    Consultant
    Quoinx Technologies Pvt Limited
    Mumbai
    ------------------------------


  • 2.  RE: LAB Testing in VM environment of WAF

    Posted 06-14-2023 10:59
    Edited by Alphonse Tognite 06-15-2023 02:23

    1)How can i create an web application so that we can test any vulnerable URL we can access from outside and how the WAF device will protect.

     

    Accessing your Lab from outside is not relative to the IMPERVA WAF GW but to your LAB  environment. Setting up a VPN to access your LAB from outside is recommended.

    Regarding the Web application, no need to create it from scratch a lot of vuln apps are available online for dev you can set up dvwa from here

    https://github.com/digininja/DVWA

     

    What would be the traffic Flow for my LAB environment?

     

    Again depending your lab environment.

    Client(win vm or linux vm) --GW----Webapp

     

    2)Which mode I will be used in my WAF device is it 'Bridge IMPVHA or Reverse proxy mode? Can anyone explain in easy method of the bridge mode and Reverse proxy mode working.

    I prefer reverse mode.

    https://community.imperva.com/blogs/ira-miga1/2020/12/07/how-to-configure-imperva-waf-reverse-proxy-mode

     

    For more information relative to topology and deployment mode :

    https://docs.imperva.com/bundle/v14.4-waf-administration-guide/page/7187.htm



    ------------------------------
    Alphonse Tognite
    ------------------------------



  • 3.  RE: LAB Testing in VM environment of WAF

    Posted 06-15-2023 01:53

    Dear Alphonse,

    Thank you for your response.

    Will create a Lab and check it out.



    ------------------------------
    Sagar E
    Consultant
    Quoinx Technologies Pvt Limited
    Mumbai
    ------------------------------



  • 4.  RE: LAB Testing in VM environment of WAF

    Posted 06-20-2023 03:35

    Dear Team,

    We have created a VM lab environment in reverse proxy mode but i am intiating a traffic it not reaching through windows application server which is behind the WAF gateway.

    what policy or sites should I create in WAF device?so that traffic will reach through WAF and then application server.

    Also is there any command to check the DROP logs or whhere we can see traffic drop logs in WAF ?

    Regards,

    Sagar



    ------------------------------
    Sagar E
    Consultant
    Quoinx Technologies Pvt Limited
    Mumbai
    ------------------------------



  • 5.  RE: LAB Testing in VM environment of WAF

    Posted 06-20-2023 04:06

    Hello, 

    here you can find the necessary information  for the  configuration  https://docs.imperva.com/bundle/v14.7-web-application-firewall-user-guide/page/70414.htm

    =====we do have this lab prebuilt for partner.  it's a modified version from the production image and is build to run on Vmware.

    To Download browse to the Imperva FTP site at ftp-us.imperva.com (or web page). Browse to the following directory: /PartnerAssets/Partner DemoVM/Imperva_On-Premises/WAF_OneBox/WAF_OneBoX_VM Download the available image, the naming will be similar to "V######_WAF_OneBox" ("######" will show the actual version of the image). Donwload also the Setup Instructions.

    =====We also have a training to help you. 

    hope this answer your question



    ------------------------------
    Alphonse Tognite
    ------------------------------