Showing posts with label WAF. Show all posts
Showing posts with label WAF. Show all posts

Wednesday, November 3, 2010

Tips for troubleshooting Imperva WAF

Tips for troubleshooting Imperva WAF:

  • statistics.csv from Setup->Gateways->the relevant GW -> the rightmost panel. 
  • get-tech-info
  • cat /opt/SecureSphere/etc/patch_level
  • download "imperva-stats-script" from Imperva site, and run script for 24 hours.


WAF - Relevant Questions to Ask

Relevant Questions to Ask for Implementing a new WAF (Imperva, Breach, etc.)

Web Server Information
----------------------
Application Name - IP Address & Port
SSL? (yes/no)
IP Type (Legal/NAT/Load Balanced)
Number of Physical Machines
Network Throughput
Web Server Vendor
Web Server Operating System
Web site type (static/dynamic)
Application Server
Web Application Vendor (custom, peoplesoft, etc..)
Web Application Language (.net, java, etc)"
Web Application Transactions per second

Database Information
------------------------------
Database Name
Machine Name or IP Address
Number of Database Servers (physical Database boxes)
Network Throughput
Database Vendor
Database Operating System type
Database Transactions per second

Imperva WAF - Export Full Config from CLI

Export the full config from the CLI of an Imperva WAF:

--
1) cd /tmp
2) full_expimp.sh