Imperva Cyber Community

communities_1.jpg
 View Only
  • 1.  Imperva Cloud WAF and IPS Exception

    Posted 2 days ago

    Hi everyone,

    I'm looking for best-practice advice.

    I'm deploying Imperva Cloud WAF in front of our Palo Alto NGFW, and I have a question regarding traffic inspection.

    Should traffic coming from Imperva Cloud WAF be excluded from IPS / Advanced Threat Prevention on the Palo Alto firewall, or should it still be inspected?

    In real-world deployments, what would be considered the best-practice approach?

    Thanks in advance.


    #AllImperva
    #CloudWAF(formerlyIncapsula)

    ------------------------------
    Piotr Kowalczyk
    Technical User
    Applus
    Barcelona
    ------------------------------


  • 2.  RE: Imperva Cloud WAF and IPS Exception
    Best Answer

    Posted yesterday

    Hi Piotr

    I would keep both active as a defense in deep strategy, even if by mistake you should except something on CWAF, you still have another layer of security that could be protecting your assets. To ensure maximum security and system performance, maintain a multi-layered defense architecture. Keep your IPS active downstream from your WAF, and do not create complete traffic exemptions. And of course, don't forget to permit only traffic from Imperva's proxies to your origin servers. Keep in mind that the IPS would probably see only encrypted traffic, unless you decrypt the traffic from the proxies to the asset. If you need any further information, just reach me anytime.

    By the way, major security compliance frameworks mandate a Defense-in-Depth approach. Maintaining both systems ensures we fulfill the distinct network and application layer requirements for PCI-DSS, ISO 27001:2022, and SOC 2.



    ------------------------------
    Martin Morey
    Sales Engineer
    Thales CSP (AppSec).
    ------------------------------



  • 3.  RE: Imperva Cloud WAF and IPS Exception

    Posted 18 hours ago
    Edited by Piotr Kowalczyk 12 hours ago
    Hi Martin

    Many thanks for your clear answer.

    Yes, we decrypt the traffic before it is inspected by the IPS, and I do like the defense-in-depth approach. My only concern was that, since Imperva acts as a proxy, it might alter incoming traffic in a way that could cause the IPS to incorrectly flag and block it. Since that doesn't seem to be the case, I'll keep our IPS configuration as it is.

    Since you've kindly offered to answer any additional questions, I was hoping you could help me with the following:

    1. Could you explain how the source IP address will appear to our firewall and web servers? As Imperva is a reverse proxy, I assume the original client IP is replaced. I'm asking because we currently maintain IP blacklists and regularly review web server and firewall logs so would be great to see original source.

    2. We use a payment provider through an iFrame, which sends payment confirmations back to our application. From time to time, we experience issues with this communication. In your opinion, what would be the best practice here? Should we simply allowlist the provider's IP addresses in Imperva, or would it be better to bypass the WAF entirely and send that traffic directly to our web servers?

    3. I've gone through the documentation and checklists, but I was wondering if you have any practical tips for someone who is new to Imperva. Are there any common mistakes to avoid or best practices you've learned from experience that may not be obvious from the documentation?

    4. One more question just came through. I need to set up a website redirection from abc.com to abcd.com (which is our primary website). What would be the best way to do this?
    5. Sorry Martin, in the meantime another question has come up. I hope you don't mind the number of questions! I have the www.abc.com domain, which points to a server with IP X.X.X.X, and I also have release.abc.com, which points to a server with IP Y.Y.Y.Y. Could you advise on the best way to configure this in Imperva? I've already created a second website for release.abc.com, but perhaps it would be better to add a SAN to the existing www.abc.com certificate and use rules to route the traffic accordingly?

    What would you recommend?

    Thank you in advance for your help.



    ------------------------------
    Piotr Kowalczyk
    Technical User
    Applus
    Barcelona
    ------------------------------