eCyWAF is an open Web Application Firewall by eCyLabs that can be used by web application owners to protect their applications from the web security threats and vulnerabilities. eCyLabs have extended the preconfigured WAF rule sets from OWASP Modsecurity core rule set to mitigate against the OWASP Top 10 web application security vulnerabilities. If you decide that a preconfigured rule matches more traffic than is necessary, or if the rule is blocking traffic that needs to be allowed, the rule can be disabled from eCyLabs Security Center or eCyWAF config files. Deploying a Docker container firewall is simple, and even adds cloud and host security protections.
eCyWAF image can be directly installed from docker hub using any of following options:
To use eCyWAF without modifying the webserver hosting the underlying application, you can configure eCyWAF as a reverse proxy. The proxy is set by default to true and the location is defined by BACKEND environment variable. The SSL is enabled by default
docker run -p 80:80 -p 443:443 -p 8080:8080 -e PROXY_SSL=on -e BACKEND=http://example.com ecylabs/ecywaf
Visit http://hostip to access example.com
Visit http://hostip:8080 to access firewall manager. Default Username: admin and Passwd: Sec4Fw#
It is often convenient to set your servername. To do this simply use the SERVER_NAME environment variable passed to docker run. By default the servername provided is localhost. Example: -e SERVERNAME=example.com
The TLS is configured by default on port 443. Note: The default configuration uses self signed certificates, to use your own certificates (recommended) COPY or mount (-v) your server.crt and server.key into /usr/local/apache2/conf/. Please remember you'll need to forward the HTTPS port.
eCyWAF developed with a pre-built dashboard which is accessible at http://localhost:8080, Host server IP and Port to be used for Firewall Management to manage the End Point firewall settings. Internal Use Only and ensure to not expose this page to internet. In this dashboard user can see the system related information, protection rules count, attack events count and event logs. This dashboard gives a glimbs system and protection details.
eCyWAF deafult version comes with standard modsec specific detection and protection rules. Our Security Center provides a facility to create your own custom rules and push them into eCyWAF instance at your server. eCyLabs has the simple access to create the rules and append it to existing rules at eCyWAF. There is no limit to add rules through eCyLabs security center.
Docker Compose is a tool that helps us overcome this problem and easily handle multiple containers at once. Docker containers communicate between themselves in networks created, implicitly or through configuration, by Docker Compose
Create a docker-compose file to run eCyWAF as a reverse proxy
version: '2'
services:
ecywaf:
image: ecylabs/ecywaf
container_name: ecywaf01
restart: always
network_mode: host
ports:
- "80:80"
- "443:443"
- "8080:8080"
environment:
- PROXY_SSL=on
- BACKEND=http://webcontainer
In Above configuration WAF intercepts traffic that runs on the port 80, hence any requests come to the server land in eCyWAF, which will scan the requests and forward the allowed one to your web application server which would be under the port 80 (assumed, this can be updated as per your configuration) The secured connection port is set as 443.
network_mode: host or network_mode: <Network Name>
Use network_mode for sharing the same networking space with the Host or the network that web application container is running. Use host for example you want to access an application that is running on your Linux PC from the container.
version: '3'
networks:
webnetnw:
driver: bridge
ipam:
config:
- subnet: 172.18.0.0/16
services:
webserver:
depends_on:
- ecywaf
image: <webserver image>
volumes:
- ./webserver_files/var/www/html:/var/www/html/
- ./ssl:/ssl_config
container_name: websrv01
restart: always
networks:
webnetnw:
ipv4_address: 172.18.0.4
expose:
- "80"
- "443"
ecywaf:
image: ecylabs/ecywaf
container_name: ecywaf01
restart: always
networks:
webnetnw:
ipv4_address: 172.18.0.5
ports:
- "80:80"
- "443:443"
- "8080:8080"
environment:
- PROXY_SSL=on
- BACKEND=http://webcontainer
Content type
Image
Digest
Size
202 MB
Last updated
about 5 years ago
docker pull ecylabs/ecywaf