IBM Verify

IBM Verify

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  ISVA 10.2.0 - Integrated Web Application Firewall (PAM)

    Posted Mon January 31, 2022 06:47 AM
    Hello,

    currently we use the ISVA integrated WAF (PAM) like it was proposed by IBM not long ago. We are very happy with this solution because it provides a very lightweigth possibility to protect our on-prem applications running over junctions (e.g. helped in case of log4j). However, we heard that there will be no updates after 31.12.2022. 

    In our use case incoming traffic is TLS-terminated at ISVA and (often) TLS-encrypted to backend.

    Is there any replacment solution or recommendation how we should do this in future ?

    Regards,
    Juergen

    ------------------------------
    Jürgen Hitt
    ------------------------------


  • 2.  RE: ISVA 10.2.0 - Integrated Web Application Firewall (PAM)

    Posted Tue February 01, 2022 06:57 AM

    Hi Juergen,

    We love the WAF in ISVA too!

    Unfortunately, it was powered by the same componentry we've used in IBMs IPS servers, and as they (and their broader support organisation) are reaching end of life at the end of 2022, 'no more updates' will be available for us to consume. We investigated alternatives, but have come up short on an alternative that can offer the same levels of convenience, strength and simplicity of the PAM powered WAF. Never say never, but in the near term, the WAF capability/usefulness of ISVA will come to a close with the last update.

    From a replacement/recommendation perspective, the ISVA team can't suggest/propose one WAF over another, in our experience however a cloud based solution seems to be the most flexible and suitable for the widest variety of solutions. These (and infact most WAFs) already and easily handle TLS traffic, and will integrate seamlessly into your ISVA deployment. It can be a bit more complicated if you're using MTLS, but its certainly possible!

    Kind Regards,

    Philip Nye



    ------------------------------
    Philip Nye
    IBM
    Gold Coast
    ------------------------------



  • 3.  RE: ISVA 10.2.0 - Integrated Web Application Firewall (PAM)

    Posted Wed February 02, 2022 02:53 AM
    Hello Philip,

    thanks for your answer.

    To understand it the right way: We can continue to use the ISVA WAF as it is but there will be no updates? Is this only for the PAM-engine or also for the PAM-signatures? And is this for feature updates or also for bug fixing?

    Regards,
    Juergen

    ------------------------------
    Jürgen Hitt
    ------------------------------



  • 4.  RE: ISVA 10.2.0 - Integrated Web Application Firewall (PAM)

    Posted Tue February 15, 2022 09:08 PM

    Hi Jurgen, Sorry missed your reply,

    Yes, the WAF will continue to operate, but no more updates will be available.

    The PAM engine and PAM signatures will no longer be 'maintained'. This is detailed on the v10.0 Whats new page:

    https://www.ibm.com/docs/en/sva/10.0.0?topic=overview-whats-new-in-this-release

    PAM Support

    The Web Application Firewall capability will reach end of service on 31st December, 2022. After this date, no further updates will be made available. Customers can continue to use the capability on an as-is basis, and support will be available for general information and existing functionality only. There will be no defect support available. See Documentation updates for known limitation.

    Hope this clarifies things for you.



    ------------------------------
    Philip Nye
    IBM
    Gold Coast
    ------------------------------



  • 5.  RE: ISVA 10.2.0 - Integrated Web Application Firewall (PAM)

    Posted Wed February 16, 2022 10:15 AM
    Phil, have you all ever thought of allowing customers to make their own signatures?  That would keep the functionality going if so.  We've been asked this a lot over the past several years, especially when the log4j stuff came out.  Our application owners kept asking us if we could just create a signature and put it in, similar to how other products work (i.e. the one that comes to my mind is Snort), instead of waiting for IBM to release a new signature pack.  Just a thought.

    Currently we are planning for ending up with some other vendor's product sitting on front of the webseal and breaking the TLS connection, and then having to essentially forge a new incoming client cert for the mTLS on our webseals to continue to work.  At least that's the direction we have been given so far.

    ------------------------------
    Matt Jenkins
    ------------------------------



  • 6.  RE: ISVA 10.2.0 - Integrated Web Application Firewall (PAM)

    Posted Thu February 17, 2022 08:18 PM

    Hey Matt,

    With the module itself being no longer developed/maintained, it's not really a practical option unfortunately.

    Regards,

    Phil



    ------------------------------
    Philip Nye
    IBM
    Gold Coast
    ------------------------------



  • 7.  RE: ISVA 10.2.0 - Integrated Web Application Firewall (PAM)

    Posted Wed February 16, 2022 10:44 AM
    Hi Phil,

    last questions regarding WAF: Will the WAF capability being removed from the appliance with the next major release (e.g. ISVA 11)?

    -Frank

    ------------------------------
    Frank Sommer
    Non-management
    IBM
    Frankfurt
    (491) 608-8101 x79
    ------------------------------



  • 8.  RE: ISVA 10.2.0 - Integrated Web Application Firewall (PAM)

    Posted Thu February 17, 2022 08:22 PM

    Hi Frank,

    With time, the 'existing' functionality will gradually become more and more obselete, removal of the function would make sense. This is the most I would say with any certainty at this time.

    Regards,

    Phil



    ------------------------------
    Philip Nye
    IBM
    Gold Coast
    ------------------------------



  • 9.  RE: ISVA 10.2.0 - Integrated Web Application Firewall (PAM)

    Posted Fri February 18, 2022 04:11 AM

    This topic is really a big trouble to us. Since we use mTLS on client and backend side (requirement of our security) and so far nobody came up with an solution, beside making a major architecture changes and introducing new communication lines. I our case hundreds of applications affected by such changes. Even if we would know a solution we are not able to do that changes like this in that timeframe. And finally log4j showed that it is crucial to have the WAF kind of functionality .



    ------------------------------
    Jürgen Hitt
    ------------------------------