DataPower

 View Only
  • 1.  Creating a Web Application Firewall in Datapower.

    Posted Thu May 09, 2024 02:12 PM

    Hi Guys,

    I want to secure a payment page using a Web Application Firewall in Datapower but i can't find good step by step tutorials or blogs for this. The payment page is using https therefore I also need to use TLS in datapower. Any effort to help me achieve this will be highly appreciated.



    ------------------------------
    Philip Muchemi
    ------------------------------


  • 2.  RE: Creating a Web Application Firewall in Datapower.

    Posted Fri May 10, 2024 12:41 PM

    Unfortunately our old developerworks site which had an example is gone and the way back machine archive does not have any of the pictures.  The best option I have found is this YouTube video which honestly has the best "run down" -- but it is using the old WebUI, now CarbonUI is becoming the default.  Hope this helps: https://www.youtube.com/watch?v=XdsSWdntwPw



    ------------------------------
    DOMINIC MICALE
    ------------------------------



  • 3.  RE: Creating a Web Application Firewall in Datapower.

    Posted Tue May 21, 2024 09:45 AM

    Hi Dominic,

    Could you please spare some time to assist me with configuring the WAF by sharing my screen? I appreciate you sending the YouTube link, but the video lacked sufficient detail, making it difficult for me to complete the configuration.

    Philip Muchemi.



    ------------------------------
    Philip Muchemi,
    Integration Consultant,
    Suluhisho Systems Limited,
    Nairobi, Kenya.
    ------------------------------



  • 4.  RE: Creating a Web Application Firewall in Datapower.

    Posted Tue May 21, 2024 01:23 PM

    Hi Philip,

    I recommend you open a support case if you need further assistance in this space, you may also have to engage services depending on what assistance you need.  This is a Q&A forum and we do not setup arrangements for meetings through this forum.  Thanks for understanding.



    ------------------------------
    DOMINIC MICALE
    ------------------------------



  • 5.  RE: Creating a Web Application Firewall in Datapower.

    IBM Champion
    Posted Wed May 22, 2024 08:56 AM

    Philip,

    Are you looking for a true and only WAF, or may you need something more complicated?

    The reason I'm stating this is most, today, use the Multi-Protocol Gateway because of its overall flexibility and features.

    With that said, there are some pretty cool features of the WAF not as easily available to the MPG (such as the Name-Value Profile).

    I'll help you with the WAF, but, let's first figure out if the WAF is the best choice for your needs.

    Is HTTP/S the only protocol you'll need to support?

    Will you need to do complex processing, or just TLS negotiation?

    Will you be transforming the requests or responses or manipulating them in some way?

    What is your firmware version?

    Do you have the integration package?



    ------------------------------
    Joseph Morgan
    ------------------------------



  • 6.  RE: Creating a Web Application Firewall in Datapower.

    Posted Mon May 27, 2024 05:10 AM

    Hi Joseph,

    Yes its only HTTP/S protocol we will be using.
    No complex processing or transformation.

    Its only our fronted payment page that we need to secure.

    Is it possible we set up a call when you have time?

    Thank you.



    ------------------------------
    Philip Muchemi,
    Integration Consultant,
    Suluhisho Systems Limited,
    Nairobi, Kenya.
    ------------------------------