WORKFLOW
Figure – VSP-Web Workflow
-
Create Web Profile – Refer Create Web Profile Section for more information
-
Application Creation – Refer Workload Onboarding for more information about Application creation. Ensure that:
-
Select the Service Type is Web Services.
-
Provide the below information:
-
Web Server Name – Name of the Web Server
-
Web Server Description – Short description of the Web Server
-
Select the appropriate Web Profile Type from the dropdown – Apache Httpd, Nginx OR IIS
-
-
Provide the below information:
-
Web Server Command Line – The exact command for starting the Web Server
Examples: service httpd start (For Apache); service nginx start (For Nginx)
-
Protection Profile (optional) – Select the appropriate Protection Profile from the dropdown
-
Host Name – List of all the associated host names separated by comma
-
Web Profile Name – Select the appropriate Web Profile from the dropdown
-
-
For HTTP Profile, ensure that Protocol Enforcement vulnerability is selected. If any Deny rule is configured for Custom Injection, ensure that it is selected
-
-
Provision Application
-
For VMs, ensure that the appropriate Instances are associated with the Application and it is secured using the below button
-
For containers, the instances are automatically associated and the Application is secured
-
-
Monitor Incidents – Based on the configured rules, the HTTP requests are allowed/blocked. The blocked requests are reported as incidents. Navigate to Monitor > Incidents to view them
-
Add Exceptions – If undesired incidents are received, create exceptions for them to prevent receiving such incidents in the future