-
Getting Started with NetScaler
-
Solutions for Telecom Service Providers
-
Load Balance Control-Plane Traffic that is based on Diameter, SIP, and SMPP Protocols
-
Provide Subscriber Load Distribution Using GSLB Across Core-Networks of a Telecom Service Provider
-
Authentication, authorization, and auditing application traffic
-
Basic components of authentication, authorization, and auditing configuration
-
-
Web proxy support for outbound calls to IDP or third party endpoints
-
Web Application Firewall protection for VPN virtual servers and authentication virtual servers
-
On-premises NetScaler Gateway as an identity provider to Citrix Cloud™
-
Authentication, authorization, and auditing configuration for commonly used protocols
-
Troubleshoot authentication and authorization related issues
-
Troubleshoot authentication, authorization and auditing issues
-
Configure EULA as an authentication factor in NetScaler nFactor system
-
Configure periodic Endpoint Analysis scan as a factor in nFactor authentication
-
Configure post-authentication Endpoint Analysis scan as a factor in NetScaler nFactor authentication
-
Configure pre-authentication Endpoint Analysis scan as a factor in nFactor authentication
-
Configure pre-auth and post-auth EPA scan as a factor in nFactor authentication
-
Configure prefill user name from certificate in NetScaler nFactor authentication
-
Configure protected user as an authentication factor in NetScaler nFactor authentication
-
Localize error messages generated by NetScaler nFactor system
-
Configure NetScaler Gateway preauthentication EPA scan for the domain check
-
-
-
-
-
-
-
Configure DNS resource records
-
Configure NetScaler as a non-validating security aware stub-resolver
-
Jumbo frames support for DNS to handle responses of large sizes
-
Caching of EDNS0 client subnet data when the NetScaler appliance is in proxy mode
-
Use case - configure the automatic DNSSEC key management feature
-
Use Case - configure the automatic DNSSEC key management on GSLB deployment
-
-
-
Source IP address whitelisting for GSLB communication channels
-
Use case: Deployment of domain name based autoscale service group
-
Use case: Deployment of IP address based autoscale service group
-
-
Persistence and persistent connections
-
Advanced load balancing settings
-
Gradually stepping up the load on a new service with virtual server–level slow start
-
Protect applications on protected servers against traffic surges
-
Retrieve location details from user IP address using geolocation database
-
Use source IP address of the client when connecting to the server
-
Use client source IP address for backend communication in a v4-v6 load balancing configuration
-
Set a limit on number of requests per connection to the server
-
Configure automatic state transition based on percentage health of bound services
-
-
Use case 2: Configure rule based persistence based on a name-value pair in a TCP byte stream
-
Use case 3: Configure load balancing in direct server return mode
-
Use case 6: Configure load balancing in DSR mode for IPv6 networks by using the TOS field
-
Use case 7: Configure load balancing in DSR mode by using IP Over IP
-
Use case 10: Load balancing of intrusion detection system servers
-
Use case 11: Isolating network traffic using listen policies
-
Use case 12: Configure Citrix Virtual Desktops for load balancing
-
Use case 13: Configure Citrix Virtual Apps and Desktops for load balancing
-
Use case 14: ShareFile wizard for load balancing Citrix ShareFile
-
Use case 15: Configure layer 4 load balancing on the NetScaler appliance
-
-
-
-
Support for hybrid Post Quantum cryptography on the frontend
-
-
Create a certificate signing request and use SSL certificates on a NetScaler appliance
-
Configure SSL acceleration with HTTP on the front end and SSL on the back end
-
Export certificates used on a NetScaler appliance as PFX file
-
Configure SSL monitoring when client authentication is enabled on the back-end service
-
Configure SSL action to forward client traffic if a cipher is not supported on the ADC
-
Configure synchronization of files in a high availability setup
-
-
-
Authentication and authorization for System Users
-
-
-
Configuring a CloudBridge Connector Tunnel between two Datacenters
-
Configuring CloudBridge Connector between Datacenter and AWS Cloud
-
Configuring a CloudBridge Connector Tunnel Between a Datacenter and Azure Cloud
-
Configuring CloudBridge Connector Tunnel between Datacenter and SoftLayer Enterprise Cloud
-
Configuring a CloudBridge Connector Tunnel Between a NetScaler Appliance and Cisco IOS Device
-
CloudBridge Connector Tunnel Diagnostics and Troubleshooting
This content has been machine translated dynamically.
Dieser Inhalt ist eine maschinelle Übersetzung, die dynamisch erstellt wurde. (Haftungsausschluss)
Cet article a été traduit automatiquement de manière dynamique. (Clause de non responsabilité)
Este artículo lo ha traducido una máquina de forma dinámica. (Aviso legal)
此内容已经过机器动态翻译。 放弃
このコンテンツは動的に機械翻訳されています。免責事項
이 콘텐츠는 동적으로 기계 번역되었습니다. 책임 부인
Este texto foi traduzido automaticamente. (Aviso legal)
Questo contenuto è stato tradotto dinamicamente con traduzione automatica.(Esclusione di responsabilità))
This article has been machine translated.
Dieser Artikel wurde maschinell übersetzt. (Haftungsausschluss)
Ce article a été traduit automatiquement. (Clause de non responsabilité)
Este artículo ha sido traducido automáticamente. (Aviso legal)
この記事は機械翻訳されています.免責事項
이 기사는 기계 번역되었습니다.책임 부인
Este artigo foi traduzido automaticamente.(Aviso legal)
这篇文章已经过机器翻译.放弃
Questo articolo è stato tradotto automaticamente.(Esclusione di responsabilità))
Translation failed!
Statistics and reports
The information maintained in the logs and statistics, and displayed in the reports, provides important guidance for configuring and maintaining the Web App Firewall.
The Web App Firewall statistics
When you enable the statistics action for Web App Firewall signatures or security checks, the Web App Firewall maintains information about connections that match that signature or security check. You can view the accumulated statistics information on the Monitoring tab by selecting one of the following choices in the Select Group list box:
- Web App Firewall. A summary of all statistics information gathered by your Web App Firewall appliance for all profiles.
- Web App Firewall (per profile). The same information, but displayed per-profile rather than summarized.
You can use this information to monitor how your Web App Firewall is operating and determine whether there is any abnormal activity or abnormal amounts of hits on a signature or security check. If you see such a pattern of abnormal activity, you can check the logs for that signature or security check to diagnose and take corrective action.
Relaxation hit statistical counter
Based on the relaxation that is applied on the violated traffic, you can also display statistical details such as the number of times a violation is occurring on the appliance, number of relaxation rules applied at the time of violation, and its last applied timestamp. By performing this, the centralized learning engine can automatically deletes unused or redundant relaxation bindings. For more information, see WAF Learn Engine topic.
The relaxation hit statistical counter is available only for the following security checks.
- Cross-site scripting
- SQL Injection
- Cookie consistency
- JSON SQL
- JSON Cross-site scripting
- JSON DoS
- JSON CMD injection
- Cross-Site request forgery
- Field format
- Starturl
- Denyurl
- Content-Type protection
To display statistics for relaxation rule hit counters by using the CLI
At the command prompt, type:
stat appfw profile p1
Example:
stat appfw profile p1 –fullvalues
Starturl Rules Statistics
| Rule | hits | Rate | last hit time |
|---|---|---|---|
| 87a4…51177 | 0 | 0 | Thu … 1970 |
| 5b83…dc12a | 0 | 0 | Thu … 1970 |
| 12345 | 0 | 0 | Thu … 1970 |
To display statistics for relaxation rule hit counters by using the GUI
Complete the following steps to view the relaxation rule hit counter statistics:
- Navigate to Security > NetScaler Web App Firewall > Profiles.
- In the details pane, select a Web App Firewall profile and click Statistics.
- The NetScaler Web App Firewall Statistics page displays the statistics details.
- You can select Tabular View or switch to Graphical View to display the data in a tabular or graphical format.
The Web App Firewall Reports
The Web App Firewall reports provide information about your Web App Firewall configuration and how it is handling traffic for your protected websites.
The PCI DSS report
The Payment Card Industry (PCI) Data Security Standard (DSS), version 4.0, consists of 12 security criteria that most credit card companies require businesses that accept online payments through credit and debit cards to meet. The criteria aret designed to prevent identity theft, hacking, and other types of fraud. If an ISP does not meet the PCI DSS criteria, the ISP or merchant might lose authorization to accept credit card payments through the website.
ISPs and online merchants prove that they are in compliance with PCI DSS by having an audit conducted by a PCI DSS Qualified Security Assessor (QSA) Company. The PCI DSS report is designed to assist them both before and during the audit. Before the audit, it shows which Web App Firewall settings are relevant to PCI DSS, how they must be configured, and (most important) whether your current Web App Firewall configuration meets the standard. During the audit, the report can be used to demonstrate compliance with a relevant PCI DSS criteria.
The PCI DSS report consists of a list of those criteria that are relevant to your Web App Firewall configuration. Under each criterion, it lists your current configuration options, indicates whether your current configuration complies with the PCI DSS criterion, and explains how to configure the Web App Firewall so that your protected websites are in compliance with the criterion.
The PCI DSS report is located under System > Reports. To generate the report as an Adobe PDF file, click Generate PCI DSS Report. Depending on your browser settings, the report is displayed in the pop-up window or you are prompted to save it to your hard disk.
Note:
To view this and other reports, you must have the Adobe Reader program installed on your computer.
The PCI DSS report consists of the following sections:
-
Description. A description of the PCI DSS Compliance Summary report.
-
Firewall License and Feature Status. Tells you whether the Web App Firewall is licensed and enabled on your NetScaler appliance.
-
Executive Summary. A table that lists the PCI DSS criteria and tells you which of those criteria are relevant to the Web App Firewall.
-
Detailed PCI DSS Criteria Information. For each PCI DSS criterion that is relevant to your Web App Firewall configuration, the PCI DSS report provides a section that contains information about whether your configuration is in compliance and, if it is not, how to bring it into compliance.
-
Configuration. Data for individual profiles, which you access either by clicking Web App Firewall Configuration at the top of the report, or directly from the Reports pane. The Web App Firewall Configuration report is the same as the PCI DSS report, with the PCI DSS-specific summary omitted.
The Web App Firewall configuration report
The Web App Firewall Configuration report is located under System > Reports. To display it, click Generate Web App Firewall Configuration Report. Depending on your browser settings, the report is displayed in the pop-up window or you are prompted to save it to your hard disk.
The Web App Firewall Configuration report starts with a Summary page, which consists of the following sections:
- Web App Firewall Policies. A table that lists your current Web App Firewall policies, showing the policy name, the content of the policy, the action (or profile) it is associated with, and global binding information.
- Web App Firewall Profiles. A table that lists your current Web App Firewall profiles and indicates which policy each profile is associated with. If a profile is not associated with a policy, the table displays INACTIVE in that location.
To download all report pages for all policies, at the top of the Profiles Summary page click Download All Profiles. You display the report page for each individual profile by selecting that profile in the table at the bottom of the screen. The Profile page for an individual profile shows whether each check action is enabled or disabled for each check, and the other configuration settings for the check.
To download a PDF file containing the PCI DSS report page for the current profile, click Download Current Profile at the top of the page. To return to the Profiles Summary page, click Web App Firewall Profiles. To go back to the main page, click Home. You can refresh the PCI DSS report at any time by clicking Refresh in the upper right corner of the browser.
Monitor Global Web App Firewall session limit
NetScaler Web App Firewall now enables monitoring of the total session capacity supported by the system. Previously, the resource-intensive nature of Web App Firewall inspection—which demands significant CPU, memory, and signature processing—created a risk of performance degradation whenever session counts exceeded limits. By providing real-time visibility into usage versus total capacity, this enhancement allows administrators to track session counts against maximum thresholds. This enables them to identify bottlenecks and scale resources proactively before performance or security is compromised.
Some of the benefits are:
- Proactive capacity planning: Monitor session trends to scale infrastructure before performance hits a bottleneck.
- Resource visibility: Understand the overall load supported across all packet engines.
- Performance stability: Prevent security degradation by staying within supported session limits.
View global Web App Firewall session statistics
Use the “Appfw DHT Max Sessions” parameter to monitor Web App Firewall session limits. The metric tracks the overall session rate per second and the total supported sessions across the system’s packet engines.
To view statistics by using CLI
At the command prompt, type: stat appfw In the output, refer to the Appfw DHT Max Sessions parameter for session capacity and current rate data
To view statistics by using GUI
- Navigate to Security > NetScaler Web App Firewall.
- In the Traffic Statistics table, Appfw DHT Max Sessions is displayed.
Share
Share
This Preview product documentation is Cloud Software Group Confidential.
You agree to hold this documentation confidential pursuant to the terms of your Cloud Software Group Beta/Tech Preview Agreement.
The development, release and timing of any features or functionality described in the Preview documentation remains at our sole discretion and are subject to change without notice or consultation.
The documentation is for informational purposes only and is not a commitment, promise or legal obligation to deliver any material, code or functionality and should not be relied upon in making Cloud Software Group product purchase decisions.
If you do not agree, select I DO NOT AGREE to exit.