Sign inSign up

ecylabs/ecywaf

By ecylabs

•Updated about 5 years ago

Web Application Firewall

Image
1

1.1K

ecylabs/ecywaf repository overview

⁠What is eCyWAF?

eCyWAF is an open Web Application Firewall by eCyLabs that can be used by web application owners to protect their applications from the web security threats and vulnerabilities. eCyLabs have extended the preconfigured WAF rule sets from OWASP Modsecurity core rule set to mitigate against the OWASP Top 10 web application security vulnerabilities. If you decide that a preconfigured rule matches more traffic than is necessary, or if the rule is blocking traffic that needs to be allowed, the rule can be disabled from eCyLabs Security Center or eCyWAF config files. Deploying a Docker container firewall is simple, and even adds cloud and host security protections.

⁠How to use this image

eCyWAF image can be directly installed from docker hub using any of following options:

⁠Docker Run - Proxying

To use eCyWAF without modifying the webserver hosting the underlying application, you can configure eCyWAF as a reverse proxy. The proxy is set by default to true and the location is defined by BACKEND environment variable. The SSL is enabled by default

  • Run the following commands to run eCyWAF as a reverse proxy
docker run -p 80:80 -p 443:443 -p 8080:8080 -e PROXY_SSL=on -e BACKEND=http://example.com ecylabs/ecywaf

It is often convenient to set your servername. To do this simply use the SERVER_NAME environment variable passed to docker run. By default the servername provided is localhost. Example: -e SERVERNAME=example.com

⁠TLS/HTTPS

The TLS is configured by default on port 443. Note: The default configuration uses self signed certificates, to use your own certificates (recommended) COPY or mount (-v) your server.crt and server.key into /usr/local/apache2/conf/. Please remember you'll need to forward the HTTPS port.

⁠About Firewall Manager

eCyWAF developed with a pre-built dashboard which is accessible at http://localhost:8080⁠, Host server IP and Port to be used for Firewall Management to manage the End Point firewall settings. Internal Use Only and ensure to not expose this page to internet. In this dashboard user can see the system related information, protection rules count, attack events count and event logs. This dashboard gives a glimbs system and protection details.

⁠eCyLabs Security Center

eCyWAF deafult version comes with standard modsec specific detection and protection rules. Our Security Center provides a facility to create your own custom rules and push them into eCyWAF instance at your server. eCyLabs has the simple access to create the rules and append it to existing rules at eCyWAF. There is no limit to add rules through eCyLabs security center.

⁠Docker Compose examples

Docker Compose is a tool that helps us overcome this problem and easily handle multiple containers at once. Docker containers communicate between themselves in networks created, implicitly or through configuration, by Docker Compose

⁠1. docker-compose for proxying

Create a docker-compose file to run eCyWAF as a reverse proxy

version: '2'

services:
   ecywaf:
	 image: ecylabs/ecywaf
	 container_name: ecywaf01
	 restart: always
	 network_mode: host
	 ports:
	   - "80:80"
	   - "443:443"
	   - "8080:8080"
	 environment:
	   - PROXY_SSL=on
	   - BACKEND=http://webcontainer

In Above configuration WAF intercepts traffic that runs on the port 80, hence any requests come to the server land in eCyWAF, which will scan the requests and forward the allowed one to your web application server which would be under the port 80 (assumed, this can be updated as per your configuration) The secured connection port is set as 443.

network_mode: host or network_mode: <Network Name>

Use network_mode for sharing the same networking space with the Host or the network that web application container is running. Use host for example you want to access an application that is running on your Linux PC from the container.

⁠2. docker-compose to build eCyWAF together with Web Server (Sample)
version: '3'

networks:
  webnetnw:
	driver: bridge
	ipam:
	  config:
		- subnet: 172.18.0.0/16

services:
   webserver:
	 depends_on:
		- ecywaf
	 image: <webserver image>
	 volumes:
		- ./webserver_files/var/www/html:/var/www/html/
		- ./ssl:/ssl_config
	 container_name: websrv01
	 restart: always
	 networks:
	   webnetnw:
		 ipv4_address: 172.18.0.4
	 expose:
	   - "80"
	   - "443"
   ecywaf:
	 image: ecylabs/ecywaf
	 container_name: ecywaf01
	 restart: always
	 networks:
	   webnetnw:
		 ipv4_address: 172.18.0.5
	 ports:
	   - "80:80"
	   - "443:443"
	   - "8080:8080"
	 environment:
	   - PROXY_SSL=on
	   - BACKEND=http://webcontainer

⁠ENV Variables

  • ACCESSLOG - A string value indicating the location of the custom log file (Default: /var/log/apache2/access.log)
  • BACKEND - A string indicating the partial URL for the remote server of the ProxyPass directive (Default: http://localhost:80⁠)
  • BACKEND_WS - A string indicating the IP/URL of the WebSocket service (Default: ws://localhost:8080)
  • ERRORLOG - A string value indicating the location of the error log file (Default: /var/log/apache2/error.log)
  • H2_PROTOCOLS - A string value indicating the protocols supported by the HTTP2 module (Default: h2 http/1.1)
  • LOGLEVEL - A string value controlling the number of messages logged to the error_log (Default: warn)
  • METRICS_ALLOW_FROM - A string indicating a range of IP adresses that can access the metrics (Default: 127.0.0.0/255.0.0.0 ::1/128)
  • METRICS_DENY_FROM - A string indicating a range of IP adresses that cannot access the metrics (Default: All)
  • METRICSLOG - A string indicating the path of the metrics log (Default: /dev/null combined)
  • PERFLOG - A string indicating the path of the performance log (Default: /dev/stdout perflogjson env=write_perflog)
  • PORT - An integer value indicating the port where the webserver is listening to (Default: 80)
  • PROXY_PRESERVE_HOST - A string indicating the use of incoming Host HTTP request header for proxy request (Default: on)
  • PROXY_SSL_CERT_KEY - A string indicating the path to the server PEM-encoded private key file (Default: /usr/local/apache2/conf/server.key)
  • PROXY_SSL_CERT - A string indicating the path to the server PEM-encoded X.509 certificate data file or token identifier (Default: /usr/local/apache2/conf/server.crt)
  • PROXY_SSL_CHECK_PEER_NAME - A string indicating if the host name checking for remote server certificates is to be enabled (Default: on)
  • PROXY_SSL_VERIFY - A string value indicating the type of remote server Certificate verification (Default: none)
  • PROXY_SSL - A string indicating SSL Proxy Engine Operation Switch (Default: off)
  • PROXY_TIMEOUT - Number of seconds for proxied requests to time out (Default: 60)
  • REMOTEIP_INT_PROXY - A string indicating the client intranet IP addresses trusted to present the RemoteIPHeader value (Default: 10.1.0.0/16)
  • SERVER_ADMIN - A string value indicating the address where problems with the server should be e-mailed (Default: root@localhost)
  • REQ_HEADER_FORWARDED_PROTO - A string indicating the transfer protocol of the initial request (Default: https)
  • SSL_ENGINE - A string indicating the SSL Engine Operation Switch (Default: off)
  • TIMEOUT - Number of seconds before receiving and sending timeout (Default: 60)
  • WORKER_CONNECTIONS - Maximum number of MPM request worker processes (Default: 400)

Tag summary

Content type

Image

Digest

Size

202 MB

Last updated

about 5 years ago

docker pull ecylabs/ecywaf