This message was deleted.
# citrix-netscaler
s
This message was deleted.
m
Yes, there are part of the gateway you can’t rewrite, so what are you trying to do?
b
trying to add security headers to the
fqdn\logon\logonpoint\index.html
and similar sections of the gateway, such as
X-Frame-Options
. Trying to shore things up in response to a security audit.
m
You can enable it from a tickbox now, under configure aaa settings if i recall right.. i don’t do a lot of gateway anymore. X-Frame-Options should be part of them
b
Gateway > Global > AAA > there's a CSP header, that's one of the headers I'm looking for. I'm comparing against SecurityHeaders.com to try to head off future audit pain as well. If you know where any more are, I'm all ears
m
You can test https://gw.netscaler.dk to see what i have on mine, those are with rewrite and without the CSP header setting on the gateway
j
Is the gw vserver bound to an aaa? There are little differences, see this for more details https://www.julianjakob.com/citrix-adc-latest-insights-about-security-headers/
💯 1
b
I'll look into these. Thank you both
k
great article @Julian Jakob, updated our ADM templates and now it's showing A in our test environment
j
Thanks Kari, any Feedback regarding the Hardening of the missing AAA part is very appreciated.
m
I have had a task to apply security headers to my Gateway VIPs. I am binding them like I have done for years, but they don't take effect until I failover HA pairs. I have a stand alone NS I need to make the same changes to and will test if downing the VIP is enough or if I need to reboot the NetScaler. I am on NS13.1-42.47 and NS13.1-37.38. I was just about to make a new thread because I think I'm losing my mind with this. The two headers I'm working with are Content-Security-Policy and X-Permitted-Cross-Domain-Policies. The built-in CSP header does not work with Duo, which is why I need a custom rewrite action/policy.
j
Did you try „flush cache contentgroup loginstaticobjects“ ? Also most scanners do also caching
b
I don't know about the rest of you, but I'm getting an unlicensed feature error when I try to run that
m
Yes. And using browser dev tools confirmed the policies were not in effect until a failover occurred.
m
Its a primium feature, wait or reboot
b
3 days waiting, no change. 🤔 That expected behavior?
m
Nope.
b
Didn't think so. Thanks for confirming.
m
In an airport right now, so can’t do much. Are you seeing hits in the policy?
b
difficult to say, policy is used with regular lbservers also. Probably should create a one-off to check against.
j
In my findings the command worked, also with standard license. You‘re getting the error but cache was refreshed. Strange
m
It would make sense, since even in standard and advanced they leverage caching on objects on the gateway, thus they should allow you to flush it. Can you check the caching group to see if it changes after the command is run?
m
@Julian Jakob, I stand corrected. I ran "shell nsapimgr_wr.sh -ys call=ns_ic_flush" from cli and the next scan worked. I thought you meant clearing the cache on the scanner, not the NetScaler. Honestly didn't know that was a thing.