﻿<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>LevelBlue Knowledge Base » Knowledgebase » Legacy Products » WAF</title><generator>InstantKB.NET 2.0.6</generator><description>LevelBlue Knowledge Base</description><link>https://support.levelblue.com/kb/</link><webMaster>website@m86security.com</webMaster><lastBuildDate>Tue, 21 Apr 2026 14:14:40 GMT</lastBuildDate><ttl>20</ttl><item><title>End-of-Life for Trustwave Web Application Firewall</title><link>https://support.levelblue.com/kb/Goto21100.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Trustwave Web Application Firewall (WAF) &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;p&gt;Trustwave is announcing the End-of-Life (EOL) for Trustwave Web Application Firewall (WAF) effective September 30, 2020. Please note that after September 30, 2020, software maintenance releases, including security patches and bug fixes, will no longer be issued for Trustwave WAF.&lt;/p&gt;&lt;p&gt;We recommend that customers currently using Trustwave WAF migrate to our new Trustwave Managed WAF offering (available beginning October 1, 2019), leveraging Akamai’s market leading solution and Trustwave market leading managed services.&lt;/p&gt;&lt;p&gt;Key dates are as follows:&lt;/p&gt;&lt;ul&gt;    &lt;li&gt;End-of-sale (EOS) effective date: September 1, 2019 &lt;/li&gt;    &lt;li&gt;End-of-life (EOL) effective date: September 30, 2020 &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;For more information on additional capabilities, benefits and migration information, see Trustwave WAF End-Of-Life Frequently Asked Questions (FAQ), attached to this article.&lt;/p&gt;&lt;p&gt;Trustwave WAF customers will be contacted by their Trustwave Account Manager with more information regarding the new platform and service as well as an explanation of the migration path to the new solution.&lt;/p&gt;&lt;p&gt;For more information or questions regarding the migration process, please contact your Trustwave Account Manager.&lt;/p&gt;</description><pubDate>Wed, 04 Sep 2019 15:50:20 GMT</pubDate><dc:creator>Charles</dc:creator></item><item><title>Manually loading the license on a standby WebDefend appliance</title><link>https://support.levelblue.com/kb/Goto14787.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WebDefend - All versions &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question: &lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;How do I upload a new license to a WebDefend appliance that is in stand-by mode? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;To manually load the license on a standby WebDefend appliance: &lt;/p&gt;&lt;ol&gt;    &lt;li&gt;Using a program such as WinSCP, copy the license to the standby WebDefend appliance to &lt;span style="font-family: courier new;"&gt;/home/bgse/pub&lt;/span&gt; &lt;/li&gt;    &lt;li&gt;SSH to the standby appliance as &lt;span style="font-family: courier new;"&gt;bgse&lt;/span&gt;, then "su -" and login as root &lt;/li&gt;    &lt;li&gt;Change to the directory:&lt;br /&gt;     &lt;br /&gt;    &lt;span style="font-family: courier new;"&gt;cd /home/bgse/pub&lt;/span&gt;&lt;br /&gt;      &lt;/li&gt;    &lt;li&gt;Copy and rename the license to the correct file name (assume for this example that the uploaded license file is 2A43C.lic):&lt;br /&gt;    &lt;br /&gt;    &lt;span style="font-family: courier new;"&gt;# cp 2A43C.lic /usr/local/opt/breach/breach.lic&lt;/span&gt; &lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;p&gt;The filename &lt;strong&gt;MUST &lt;/strong&gt;be &lt;span style="font-family: courier new;"&gt;breach.lic&lt;/span&gt;&lt;/p&gt;</description><pubDate>Thu, 04 May 2017 05:54:23 GMT</pubDate><dc:creator>Piotr Dłubisz</dc:creator></item><item><title>Upgrade to version 8.0 fails (jntm fails to start services)</title><link>https://support.levelblue.com/kb/Goto20791.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Trustwave WAF (WebDefend) &lt;/li&gt;    &lt;li&gt;Upgrading to version 8.0 from 7.5 and up. &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Problem:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;After upgrade to WAF 8.0, services will not start. &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Symptoms:&lt;/h2&gt;&lt;h3&gt;Error in jntm logs:&lt;/h3&gt;&lt;pre&gt;2017-01-26 17:30:27,349 ERROR[org.jboss.as.controller.management-operation] (Controller Boot Thread)JBAS014613: Operation ("add") failed - address:([("interface" =&amp;gt; "external")]) - failure description:"JBAS014704: '' is an invalid value for parameter inet-address. Values must have a minimum length of 1 characters"2017-01-26 17:30:27,350 FATAL [org.jboss.as.server](Controller Boot Thread) JBAS015957: Server boot has failed in an unrecoverable manner; exiting. See previous messages for details.2017-01-26 17:30:27,368 INFO  [org.jboss.as] (MSCservice thread 1-10) JBAS015950: WildFly 8.2.0.Final "Tweek" stopped in 12ms&lt;/pre&gt;&lt;h3&gt;Verify Issue:&lt;/h3&gt;&lt;p&gt;In the file &lt;span style="font-family: &amp;quot;courier new&amp;quot;;"&gt;/opt/breach/bwd/jntm/configuration/standalone.xml&lt;/span&gt; the entry for &lt;span style="font-family: &amp;quot;courier new&amp;quot;;"&gt;&amp;lt;interface name="external"&amp;gt;.&amp;lt;inet-address value&amp;gt;&lt;/span&gt; is blank. &lt;/p&gt;&lt;p&gt;Example of bad configuration:&lt;/p&gt;&lt;pre&gt;&amp;lt;interfacename="external"&amp;gt;&amp;lt;inet-address value=""/&amp;gt;&amp;lt;/interface&amp;gt;&lt;/pre&gt;&lt;h2&gt;Resolution: &lt;/h2&gt;&lt;ol&gt;    &lt;li&gt;Replace the file &lt;span style="font-family: &amp;quot;courier new&amp;quot;;"&gt;maintenance.conf&lt;/span&gt;  in &lt;span style="font-family: &amp;quot;courier new&amp;quot;;"&gt;/opt/breach/bwd&lt;/span&gt; with &lt;span style="font-family: &amp;quot;courier new&amp;quot;;"&gt;maintenance.conf.oldver&lt;/span&gt; &lt;/li&gt;    &lt;li&gt;Restart services. &lt;/li&gt;&lt;/ol&gt;</description><pubDate>Thu, 02 Feb 2017 15:17:14 GMT</pubDate><dc:creator>James Swart</dc:creator></item><item><title>Preventing "Slow HTTP" Attacks</title><link>https://support.levelblue.com/kb/Goto20755.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WAF 8.0 &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Can Trustwave WAF detect and mitigate "slow HTTP" attacks? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;p&gt;Yes, WAF 8.0 and above can detect, report, and prevent slow client Denial of Service (DoS) attacks, where an attacker deliberately sends multiple partial HTTP requests to the server. &lt;/p&gt;&lt;p&gt;In such an attack, the client attempts to consume server resources by slowing the request or response, holding connections and memory resources open on the server for a long time, but without triggering session time-outs. This behavior can make the server unable to respond to legitimate requests from other clients.&lt;/p&gt;&lt;h2&gt;&lt;/h2&gt;</description><pubDate>Mon, 23 Jan 2017 18:38:58 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>Resetting a forgotten password from the Maintenance Tool (SSH) in WebDefend Version 5.1 and above</title><link>https://support.levelblue.com/kb/Goto15303.aspx</link><description>&lt;span&gt;&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WebDefend (WAF) 5.1 and above &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;I've locked my user out of the console (GUI) &lt;/li&gt;    &lt;li&gt;How do I reset my user password? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="color: #c00000;"&gt;Note:&lt;/span&gt;&lt;/strong&gt; &lt;span style="color: #c00000;"&gt;This procedure will require you to stop services on the appliance.&lt;/span&gt;&lt;/p&gt;&lt;/span&gt;&lt;ol&gt;    &lt;li&gt;    &lt;p&gt;&lt;strong&gt;Log into the appliance via ssh&lt;/strong&gt; with elevated privileges using either of the methods below. &lt;/p&gt;    &lt;ol style="list-style-type: lower-alpha;"&gt;        &lt;li&gt;Log in as &lt;span style="font-family: &amp;quot;courier new&amp;quot;;"&gt;bgse&lt;/span&gt; then switch to root &lt;span style="font-family: &amp;quot;courier new&amp;quot;;"&gt;su -&lt;/span&gt;  &lt;br /&gt;        &lt;ul&gt;            &lt;li&gt;Run the following command to start the bgoperator: &lt;span style="font-family: &amp;quot;courier new&amp;quot;;"&gt;su - bgoperator&lt;/span&gt; &lt;/li&gt;        &lt;/ul&gt;        &lt;/li&gt;        &lt;li&gt;ssh directly as bgoperator, which will run the bgoperator menu. &lt;/li&gt;    &lt;/ol&gt;    &lt;div style="border-width: 1px; border-style: solid; border-color: gray; width: 500px; color: black; margin-top: 6px; background-color: silver;"&gt;    &lt;p style="font-size: 13px; font-family: helvetica, arial, sans-serif; background-image: none; color: #333333; padding: 0px; margin: 10px 0px; line-height: 17px;"&gt;Maintenance tool - Version 5.1 (7.10.107)&lt;br /&gt;    bwd-7.10.107-1&lt;br /&gt;    Machine Type is: STAND-ALONE&lt;br /&gt;    Deployment Mode is: OUT OF LINE&lt;/p&gt;    &lt;p style="font-size: 13px; font-family: helvetica, arial, sans-serif; background-image: none; color: #333333; padding: 0px; margin: 10px 0px; line-height: 17px;"&gt;---------&lt;br /&gt;    Main Menu&lt;br /&gt;    ---------&lt;br /&gt;    1 -- Online Menu&lt;br /&gt;    2 -- Offline Menu&lt;br /&gt;    3 -- System Menu&lt;br /&gt;    ? -- Help&lt;/p&gt;    &lt;/div&gt;    &lt;/li&gt;    &lt;li&gt;    &lt;p&gt;&lt;strong&gt;Chose option 2&lt;/strong&gt; -- Offline Menu &lt;/p&gt;    &lt;div style="border-width: 1px; border-style: solid; border-color: gray; width: 500px; color: black; margin-top: 6px; background-color: silver;"&gt;    &lt;p style="font-size: 13px; font-family: helvetica, arial, sans-serif; background-image: none; color: #333333; padding: 0px; margin: 10px 0px; line-height: 17px;"&gt;------------&lt;br /&gt;    Offline Menu&lt;br /&gt;    ------------&lt;br /&gt;    1 -- Configuration Menu&lt;br /&gt;    2 -- Import - Export Menu&lt;br /&gt;    3 -- System Events Menu&lt;br /&gt;    4 -- DB maintenance Menu&lt;br /&gt;    5 -- License Management Menu&lt;br /&gt;    6 -- Audit Log Menu&lt;br /&gt;    q -- Return to Previous Menu&lt;br /&gt;    ? -- Help&lt;/p&gt;    &lt;/div&gt;    &lt;/li&gt;    &lt;li&gt;    &lt;p&gt;&lt;strong&gt;Choose option 1&lt;/strong&gt; -- Configuration Menu&lt;/p&gt;    &lt;strong&gt;&lt;span style="color: #c00000;"&gt;Note:&lt;/span&gt;&lt;/strong&gt; &lt;span style="color: #c00000;"&gt;This will require you to stop services on the appliance.&lt;/span&gt;&lt;br /&gt;    &lt;br /&gt;    &lt;div style="border-width: 1px; border-style: solid; border-color: gray; width: 500px; color: black; margin-top: 6px; background-color: silver;"&gt;    &lt;p style="font-size: 13px; font-family: helvetica, arial, sans-serif; background-image: none; color: #333333; padding: 0px; margin: 10px 0px; line-height: 17px;"&gt;----------------------&lt;/p&gt;    &lt;p style="font-size: 13px; font-family: helvetica, arial, sans-serif; background-image: none; color: #333333; padding: 0px; margin: 10px 0px; line-height: 17px;"&gt;Configuration Menu&lt;br /&gt;    ------------------&lt;br /&gt;    1 -- Reset all configuration&lt;br /&gt;    2 -- Initial Settings&lt;br /&gt;    3 -- Change user type from remote to local&lt;br /&gt;    4 -- Reset WebDefend Console user list to default users and passwords&lt;br /&gt;    5 -- Unlock all WebDefend Console users and set their passwords to the default value&lt;br /&gt;    6 -- Unlock WebDefend Console user and set password to the default value&lt;br /&gt;    7 -- Reset log files&lt;br /&gt;    8 -- Networks interface cards (NICs) roles&lt;br /&gt;    9 -- Advanced Inline configurations&lt;br /&gt;    10 -- Enable/disable signature matching for HTTP free-form parameters&lt;br /&gt;    11 -- BreachMarks Boundaries Menu&lt;br /&gt;    q -- Return to Previous Menu&lt;br /&gt;    ? -- Help&lt;/p&gt;    &lt;/div&gt;    &lt;/li&gt;    &lt;li&gt;    &lt;p&gt;&lt;strong&gt;Choose option 6&lt;/strong&gt; -- Unlock WebDefend Console user and set password to the default value. &lt;/p&gt;    &lt;ul&gt;        &lt;li&gt;You will see something similar to the output below. &lt;/li&gt;    &lt;/ul&gt;    &lt;div style="border-width: 1px; border-style: solid; border-color: gray; width: 500px; color: black; margin-top: 6px; background-color: silver;"&gt;    &lt;p style="font-size: 13px; font-family: helvetica, arial, sans-serif; background-image: none; color: #333333; padding: 0px; margin: 10px 0px; line-height: 17px;"&gt;All services are down&lt;br /&gt;    The following users were found:&lt;br /&gt;    User's ID= 1 Name= bgadmin Organization=1&lt;br /&gt;    User's ID= 2 Name= bgse Organization=1&lt;br /&gt;    User's ID= 3 Name= bob Organization=1&lt;br /&gt;    User's ID= 4 Name= jim Organization=1&lt;br /&gt;    User's ID= 5 Name= bill Organization=1&lt;br /&gt;    Enter user's ID&lt;br /&gt;    &amp;gt;&lt;/p&gt;    &lt;/div&gt;    &lt;/li&gt;    &lt;li&gt;    &lt;p&gt;Enter the user id number. The system will ask if you want to proceed. &lt;/p&gt;    &lt;ul&gt;        &lt;li&gt;Type yes. &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;    &lt;li&gt;    &lt;p&gt;Once the user's password has been reset you must start the services. Press 'q' several times to get back to the main menu. &lt;/p&gt;    &lt;div style="border-width: 1px; border-style: solid; border-color: gray; width: 500px; color: black; margin-top: 6px; background-color: silver;"&gt;---------&lt;br /&gt;    &lt;p style="font-size: 13px; font-family: helvetica, arial, sans-serif; background-image: none; color: #333333; padding: 0px; margin: 10px 0px; line-height: 17px;"&gt;Main Menu&lt;br /&gt;    ---------&lt;br /&gt;    1 -- Online Menu&lt;br /&gt;    2 -- Offline Menu&lt;br /&gt;    3 -- System Menu&lt;br /&gt;    ? -- Help&lt;/p&gt;    &lt;/div&gt;    &lt;/li&gt;    &lt;li&gt;    &lt;p&gt;&lt;strong&gt;Choose option 1&lt;/strong&gt; -- Online Menu&lt;/p&gt;    &lt;div style="border-width: 1px; border-style: solid; border-color: gray; width: 500px; color: black; margin-top: 6px; background-color: silver;"&gt;-----------&lt;br /&gt;    &lt;p style="font-size: 13px; font-family: helvetica, arial, sans-serif; background-image: none; color: #333333; padding: 0px; margin: 10px 0px; line-height: 17px;"&gt;Online Menu&lt;br /&gt;    -----------&lt;br /&gt;    1 -- WebDefend System Commands Menu&lt;br /&gt;    2 -- WebDefend Enterprise Manager Commands Menu&lt;br /&gt;    3 -- WebDefend Service Commands Menu&lt;br /&gt;    4 -- WebDefend Watchdog Menu&lt;br /&gt;    q -- Return to Previous Menu&lt;br /&gt;    ? -- Help&lt;/p&gt;    &lt;/div&gt;    &lt;/li&gt;    &lt;li&gt;    &lt;p&gt;&lt;strong&gt;Choose option 1&lt;/strong&gt; -- WebDefend System Commands Menu&lt;/p&gt;    &lt;div style="border-width: 1px; border-style: solid; border-color: gray; width: 500px; color: black; margin-top: 6px; background-color: silver;"&gt;-----------------------------&lt;br /&gt;    &lt;p style="font-size: 13px; font-family: helvetica, arial, sans-serif; background-image: none; color: #333333; padding: 0px; margin: 10px 0px; line-height: 17px;"&gt;WebDefend System Commands Menu&lt;br /&gt;    ------------------------------&lt;br /&gt;    1 -- WebDefend System Status&lt;br /&gt;    2 -- Start WebDefend System&lt;br /&gt;    3 -- Stop WebDefend System&lt;br /&gt;    q -- Return to Previous Menu&lt;br /&gt;    ? -- Help&lt;/p&gt;    &lt;/div&gt;    &lt;/li&gt;    &lt;li&gt;    &lt;p&gt;&lt;strong&gt;Choose option 2&lt;/strong&gt; -- Start WebDefend System&lt;/p&gt;    &lt;/li&gt;    &lt;li&gt;    &lt;p&gt;After the services have started, log in to the console with the user name and default password. &lt;/p&gt;    &lt;ul&gt;        &lt;li&gt;&lt;strong&gt;Note: &lt;/strong&gt;Please refer to the WebDefend &lt;em&gt;Getting Started Guide &lt;/em&gt;for the default password. &lt;/li&gt;    &lt;/ul&gt;    &lt;p&gt;You will be prompted to enter and verify a new password and select a location (default C:) to store the .prk file. &lt;/p&gt;    &lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Default passwords can be found in the WebDefend &lt;em&gt;Getting Started Guide&lt;/em&gt;. &lt;/li&gt;    &lt;li&gt;Trustwave highly recommends changing the default password. Passwords must be PCI compliant. &lt;/li&gt;    &lt;li&gt;The Reset User Password option is disabled for remotely authenticated users. For more information, see "Remote User Authentication" in the WebDefend &lt;em&gt;User Guide&lt;/em&gt;. Contact your LDAP administrator to reset a password for a remote user that is authenticated via LDAP. &lt;/li&gt;&lt;/ul&gt;</description><pubDate>Mon, 23 Jan 2017 18:38:42 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>Cannot log in to WAF due to expired certificate</title><link>https://support.levelblue.com/kb/Goto20637.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WAF (WebDefend) 7.6 GA and older. &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Symptoms:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Cannot log in to WAF from the console &lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;h2&gt;Causes:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;The certificate used for authentication has expired as of 10 July 2016 &lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h2&gt;Resolution:&lt;/h2&gt;&lt;p&gt;To resolve this issue, download and install new certificate files.&lt;/p&gt;&lt;ol&gt;    &lt;li&gt;Updated certificates are available for download from the Trustwave Support Portal (&lt;a href="https://login.trustwave.com/" class="ApplyClass" target="_blank"&gt;https://login.trustwave.com/&lt;/a&gt;).    &lt;ul style="padding-bottom: 3px;"&gt;        &lt;li&gt;Log in to the portal and navigate to File Library &amp;gt; private &amp;gt; WAF &amp;gt; WebDefend &amp;gt; Console certificate &amp;gt; newcerts.zip &lt;/li&gt;        &lt;li&gt;If you do not have permission to access this file, contact Trustwave TAC. &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;    &lt;li&gt;Download this file from the location above in the Trustwave Support Portal. &lt;/li&gt;    &lt;li&gt;Copy the zip file to each WAF appliance (&lt;span style="font-family: &amp;quot;courier new&amp;quot;;"&gt;/home/bgse/pub&lt;/span&gt;) using WinSCP or other copying methods. &lt;/li&gt;    &lt;li&gt;Log in to the WAF system. &lt;/li&gt;    &lt;li&gt;Change to the &lt;span style="font-family: &amp;quot;courier new&amp;quot;;"&gt;/home/bgse/pub&lt;/span&gt; directory (must be root). &lt;/li&gt;    &lt;li&gt;Unzip the file while in the &lt;span style="font-family: &amp;quot;courier new&amp;quot;;"&gt;/home/bgse/pub&lt;/span&gt; directory. &lt;/li&gt;    &lt;li&gt;Replace the ca.crt file in&lt;span style="font-family: &amp;quot;courier new&amp;quot;;"&gt; /opt/breach/bwd/common&lt;/span&gt; with the new file:&lt;br /&gt;    &lt;span style="font-family: &amp;quot;courier new&amp;quot;;"&gt;# cp /home/bgse/pub/ca.crt /opt/breach/bwd/common/ca.crt&lt;br /&gt;    &lt;/span&gt;&lt;/li&gt;    &lt;li&gt;Replace the console.crt file in &lt;span style="font-family: &amp;quot;courier new&amp;quot;;"&gt;/opt/breach/bwd/conf&lt;/span&gt; with the new file:&lt;br /&gt;    &lt;span style="font-family: &amp;quot;courier new&amp;quot;;"&gt;# cp /home/bgse/pub/console.crt /opt/breach/bwd/conf/console.crt&lt;/span&gt; &lt;/li&gt;    &lt;li&gt;Replace the console.jks file in&lt;span style="font-family: &amp;quot;courier new&amp;quot;;"&gt; /opt/breach/reporting/&lt;/span&gt; with the new file:&lt;br /&gt;    &lt;span style="font-family: &amp;quot;courier new&amp;quot;;"&gt;# cp /home/bgse/pub/console.jks /opt/breach/reporting/console.jks&lt;/span&gt; &lt;/li&gt;    &lt;li&gt;Restart all services using one of the following methods:    &lt;ul style="padding-bottom: 3px;"&gt;        &lt;li&gt;From root, su bgoperator then use menu options 1, 1, 4 restart services &lt;/li&gt;        &lt;li&gt;From the command line interface: &lt;span style="font-family: &amp;quot;courier new&amp;quot;;"&gt;service all_services_init restart&lt;/span&gt; &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;    &lt;li&gt;On PCs where the console is installed:    &lt;ul&gt;        &lt;li&gt;Ensure the Console is not running &lt;/li&gt;        &lt;li&gt;Replace the file console.crt in&lt;span style="font-family: &amp;quot;courier new&amp;quot;;"&gt; %BGD_HOME%\conf_tools&lt;/span&gt; with the new file. &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;On a distributed WAF installation, the WAF certificates &lt;strong&gt;must&lt;/strong&gt; be replaced and services restarted on &lt;strong&gt;all machines&lt;/strong&gt; (the NTM and the sensors). &lt;/li&gt;    &lt;li&gt;If you are connecting to a Terminal Server or using Remote Desktop, you must upgrade to version 7.6. This is required due to an issue with Windows reading the user rights.  &lt;/li&gt;&lt;/ul&gt;</description><pubDate>Mon, 23 Jan 2017 18:38:05 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>SSL Termination with WAF 7.6 and above</title><link>https://support.levelblue.com/kb/Goto20623.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WebDefend 7.6 and above &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Can WAF perform SSL Termination? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Reply:&lt;/h2&gt;&lt;p&gt;Yes, WAF 7.6 and above provides the option of "SSL Termination" (decoding client requests and passing the requests to the web server as unencrypted HTTP).&lt;/p&gt;&lt;p&gt;&lt;img alt="" style="height: 218px; width: 600px;" src="https://support.levelblue.com/kb/Uploads/Images/site/WAFTermination.png" /&gt;&lt;/p&gt;&lt;ul&gt;    &lt;li&gt;    &lt;div class="MsoNormal"&gt;&lt;span style="font-weight: normal;"&gt;In the WAF console you will find a new protocol available when configuring network settings: &lt;strong&gt;SSL Termination&lt;/strong&gt;. &lt;/span&gt;&lt;/div&gt;    &lt;/li&gt;    &lt;li&gt;    &lt;div class="MsoNormal"&gt;When you &lt;span style="font-weight: normal;"&gt;choose this configuration, you can configure different ports for WS (web server) and WAF. &lt;/span&gt;&lt;/div&gt;    &lt;/li&gt;    &lt;li&gt;    &lt;div class="MsoNormal"&gt;&lt;span style="font-weight: normal;"&gt;In the example below:&lt;/span&gt;&lt;/div&gt;    &lt;ul&gt;        &lt;li&gt;        &lt;div class="MsoNormal"&gt;&lt;span style="font-weight: normal;"&gt;Encrypted traffic is sent to WAF on port 443. &lt;/span&gt;&lt;/div&gt;        &lt;/li&gt;        &lt;li&gt;        &lt;div class="MsoNormal"&gt;&lt;span style="font-weight: normal;"&gt;WAF opens and inspects the traffic, and then forwards the decoded traffic to the web server on port 80.&lt;/span&gt;&lt;/div&gt;        &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span style="font-weight: normal;"&gt;&lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/site/WAFTermination2.png" /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description><pubDate>Mon, 09 Jan 2017 07:49:16 GMT</pubDate><dc:creator>James Swart</dc:creator></item><item><title>Finding the Open SSL Version used by WAF</title><link>https://support.levelblue.com/kb/Goto20615.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;All Versions of WAF &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li style="line-height: 11px;"&gt;How can I tell what version of SSL the WAF is using? &lt;/li&gt;    &lt;li style="line-height: 11px;"&gt;The SSL Spec for WAF 7.5 SP4 shows that WAF uses OpenSSL 1.0.1s. However, in /opt/breach/bwd/lib the versions of both libssl and libcrypto appear as 1.0.0.  &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;WAF installs and uses its own copy of OpenSSL executables. This may not be the same version as the OpenSSL provided by the operating system.&lt;/p&gt;&lt;p&gt;To determine the version of OpenSSL used by WAF:&lt;/p&gt;&lt;ol&gt;    &lt;li&gt;Connect to the WAF server using SSH &lt;/li&gt;    &lt;li&gt;Log in as BGSE&amp;gt; su - for root.  &lt;/li&gt;    &lt;li&gt;Type: &lt;br /&gt;     &lt;br /&gt;         &lt;span style="font-family: courier new;"&gt;# export LD_LIBRARY_PATH=/opt/breach/bwd/lib; /opt/breach/bwd/bin/openssl version&lt;br /&gt;     &lt;/span&gt; &lt;/li&gt;    &lt;li&gt;You can also determine the version of OpenSSL used by the operating system by simply typing:&lt;br /&gt;    &lt;br /&gt;         # &lt;span style="font-family: courier new;"&gt;openssl version&lt;/span&gt; &lt;/li&gt;&lt;/ol&gt;</description><pubDate>Mon, 10 Oct 2016 06:00:34 GMT</pubDate><dc:creator>Piotr Dłubisz</dc:creator></item><item><title>Resetting a forgotten WebDefend root password</title><link>https://support.levelblue.com/kb/Goto19598.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WAF/WebDefend 5.X and above. &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;I'm locked out of the root account. How do I reset it? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;&lt;strong&gt;Note: &lt;/strong&gt;These procedures require physical access to the WebDefend appliance and will take the system offline for the duration of the procedure. &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;For 6.x&lt;/h3&gt;&lt;ol&gt;    &lt;li&gt;Reboot or power cycle the WebDefend appliance.    &lt;ul&gt;        &lt;li&gt;&lt;strong&gt;Note:&lt;/strong&gt; The device starts and gives the option "to enter bios press Delete". Do not press Delete at this point, but wait for a second screen to display and then quickly press &lt;strong&gt;Delete&lt;/strong&gt;. &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;    &lt;li&gt;Press the &lt;strong&gt;Delete&lt;/strong&gt; key repeatedly until you see the GNU Grub.    &lt;ul&gt;        &lt;li&gt;If connected directly to the physical console (VGA), enter &lt;strong&gt;Single Mode&lt;/strong&gt;. &lt;/li&gt;        &lt;li&gt;If connected through the serial port, enter &lt;strong&gt;Single mode – Serial console&lt;/strong&gt;. &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;    &lt;li&gt;This should boot the system up in single user mode. &lt;/li&gt;    &lt;li&gt;You can then change the password using the following command:&lt;br /&gt;    &lt;br /&gt;    &lt;span style="font-family: courier new;"&gt;passwd&lt;/span&gt;&lt;br /&gt;    &lt;br /&gt;    For bgse: &lt;br /&gt;    &lt;br /&gt;    &lt;span style="font-family: courier new;"&gt;passwd bgse&lt;/span&gt;&lt;br /&gt;      &lt;/li&gt;    &lt;li&gt;Once you have successfully changed the password you can then reboot the appliance by issuing the following command:&lt;br /&gt;    &lt;br /&gt;    &lt;span style="font-family: courier new;"&gt;reboot &lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;h3&gt;For 5.X&lt;/h3&gt;&lt;ol&gt;    &lt;li&gt;Reboot or power cycle the WebDefend appliance. &lt;/li&gt;    &lt;li&gt;Press the &lt;strong&gt;Delete&lt;/strong&gt; key repeatedly until you see the BIOS password screen. &lt;/li&gt;    &lt;li&gt;Press the &lt;strong&gt;Escape&lt;/strong&gt; key and immediately start pressing the &lt;strong&gt;Delete&lt;/strong&gt; key again repeatedly (NOTE: You have to do this fairly quickly) &lt;/li&gt;    &lt;li&gt;At this point you should see the Grub screen. &lt;/li&gt;    &lt;li&gt;Press &lt;strong&gt;p&lt;/strong&gt; for password and enter the password and press enter. (Contact Trustwave TAC for the bios password.) &lt;/li&gt;    &lt;li&gt;Select the second line:&lt;br /&gt;    &lt;br /&gt;    &lt;span style="font-family: courier new;"&gt;ro root=/dev/md2 quiet console=ttyS1,9600n8&lt;/span&gt; &lt;br /&gt;      &lt;/li&gt;    &lt;li&gt;Press &lt;strong&gt;e&lt;/strong&gt; for edit. &lt;/li&gt;    &lt;li&gt;Modify the line to read &lt;br /&gt;    &lt;br /&gt;    &lt;span style="font-family: courier new;"&gt;ro root=/dev/md2 single&lt;/span&gt; &lt;br /&gt;      &lt;/li&gt;    &lt;li&gt;Press enter, and then &lt;strong&gt;b&lt;/strong&gt; for boot. &lt;/li&gt;    &lt;li&gt;This should boot the system up in single user mode. &lt;/li&gt;    &lt;li&gt;You can then change the password using the following command:&lt;br /&gt;    &lt;br /&gt;    &lt;span style="font-family: courier new;"&gt;passwd&lt;/span&gt;&lt;br /&gt;      &lt;/li&gt;    &lt;li&gt;Once you have successfully changed the password you can then reboot the appliance by issuing the following command:&lt;br /&gt;    &lt;br /&gt;    &lt;span style="font-family: courier new;"&gt;reboot &lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;</description><pubDate>Mon, 10 Oct 2016 05:00:23 GMT</pubDate><dc:creator>Piotr Dłubisz</dc:creator></item><item><title>Disabling Simulation Mode on multiple policies</title><link>https://support.levelblue.com/kb/Goto20672.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Webdefend 7.6 &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;How can I disable Simulation Mode on multiple policies in Policy Manager? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;ol&gt;    &lt;li&gt;Log in to Trustwave WAF Console &lt;/li&gt;    &lt;li&gt;Navigate to Policy Manager &lt;/li&gt;    &lt;li&gt;Select the policy you want to change &lt;/li&gt;    &lt;li&gt;In the &lt;strong&gt;Filter By Action&lt;/strong&gt; pane    &lt;ul&gt;        &lt;li&gt;Unselect "All" &lt;/li&gt;        &lt;li&gt;Select Prevention Mode "Simulated" &lt;/li&gt;        &lt;li&gt;Click &lt;strong&gt;Apply&lt;br /&gt;        &lt;/strong&gt; &lt;br /&gt;        &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/20672/waf_filter1.PNG" /&gt; &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;    &lt;li&gt;Right click the policy name and select "Update Actions for Multiple Events"&lt;br /&gt;     &lt;br /&gt;    &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/20672/waf_filter2.PNG" /&gt;&lt;br /&gt;      &lt;/li&gt;    &lt;li&gt;Uncheck "Simulation Mode" and then click &lt;strong&gt;OK&lt;/strong&gt;.&lt;br /&gt;     &lt;br /&gt;    &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/20672/waf_filter3.PNG" /&gt; &lt;/li&gt;&lt;/ol&gt;&lt;p&gt; &lt;/p&gt;&lt;br /&gt;</description><pubDate>Mon, 10 Oct 2016 04:55:31 GMT</pubDate><dc:creator>Piotr Dłubisz</dc:creator></item><item><title>Exporting certificates (including intermediate certificates) from IIS for WAF import</title><link>https://support.levelblue.com/kb/Goto19469.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WAF (WebDefend) 6.X &lt;/li&gt;    &lt;li&gt;WAF (WebDefend) 7.X &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;How do I export certificates from an IIS server for import to WebDefend? &lt;/li&gt;    &lt;li&gt;I need the export to include intermediate certificates. &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; You can only use this procedure if the certificate Private Key was marked as "Exportable" in IIS. &lt;/p&gt;&lt;ol&gt;    &lt;li&gt;On the IIS server, click Start -&amp;gt; &lt;strong&gt;Run&lt;/strong&gt; &lt;/li&gt;    &lt;li&gt;Type &lt;span style="font-family: 'courier new';"&gt;mmc&lt;/span&gt; and then click &lt;strong&gt;OK&lt;/strong&gt; &lt;/li&gt;    &lt;li&gt;In the Microsoft Management Console (MMC), click File -&amp;gt; &lt;strong&gt;Add/Remove Snap-in…&lt;/strong&gt; &lt;/li&gt;    &lt;li&gt;Select &lt;span style="font-family: 'courier new';"&gt;Certificates&lt;/span&gt; and then click &lt;strong&gt;Add&lt;/strong&gt; &lt;/li&gt;    &lt;li&gt;Select Computer Account, and then click &lt;strong&gt;Next&lt;/strong&gt; &lt;/li&gt;    &lt;li&gt;Select Local Computer and then click &lt;strong&gt;Finish&lt;/strong&gt; &lt;/li&gt;    &lt;li&gt;On the Add/Remove Snap-ins window, click &lt;strong&gt;OK&lt;/strong&gt;.    &lt;ul&gt;        &lt;li&gt;You will see the Certificates Snap-In in the MMC menu tree. &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;    &lt;li&gt;Expand the Certificates tree and find the certificate of your website (usually under Certificates -&amp;gt; Personal -&amp;gt; Certificates) &lt;/li&gt;    &lt;li&gt;Right click your certificate and click All Tasks -&amp;gt; Export &lt;/li&gt;    &lt;li&gt;The Certificate Export Wizard opens. Click &lt;strong&gt;Next&lt;/strong&gt; &lt;/li&gt;    &lt;li&gt;Select &lt;em&gt;Yes, export the private key&lt;/em&gt; and click &lt;strong&gt;Next&lt;/strong&gt; &lt;/li&gt;    &lt;li&gt;Select &lt;span style="font-family: 'courier new';"&gt;Personal Information Exchange – PKCS #12 (.PFX)&lt;/span&gt; &lt;/li&gt;    &lt;li&gt;Select &lt;span style="font-family: 'courier new';"&gt;include all certificates…&lt;/span&gt; to include the intermediate certificates. &lt;/li&gt;    &lt;li&gt;Enter a the password to secure the exported .pfx certificate file. &lt;/li&gt;    &lt;li&gt;Pick a location to save the exported .pfx certificate file, and then click  -&amp;gt; Save -&amp;gt; Finish &lt;/li&gt;&lt;/ol&gt;</description><pubDate>Tue, 19 Jan 2016 14:02:47 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>Information to gather when a WAF disk drive is suspected to have failed</title><link>https://support.levelblue.com/kb/Goto20164.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WAF 6.x &lt;/li&gt;    &lt;li&gt;WAF 7.x &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;What information do I need to gather when a WAF disk drive is not functioning correctly? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;p&gt;When you have an issue with a disk (led is blinking, corrupted data) please deliver the results of the following commands to support or the RMA team:&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: 'courier new';"&gt;# rpm -q bwd&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: 'courier new';"&gt;# df -hl&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: 'courier new';"&gt;# cat /proc/mdstat&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: 'courier new';"&gt;# ll /dev/disk/by-id&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: 'courier new';"&gt;# dmidecode --s system-serial-number&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;    &lt;li&gt;If the serial number is 0123456789 you will need to physically look for the serial number on top of the appliance &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;# In Main Menu in bgoperator 3, 6, 1 network settings&lt;/strong&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;h3&gt;Expected output:&lt;/h3&gt;&lt;p&gt;The text below shows samples of the expected output of the above commands.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;[root@waf31c ~]# rpm -q bwd&lt;/strong&gt;&lt;/p&gt;&lt;pre&gt;&lt;p&gt;bwd-9.03.112-1.x86_64&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;/pre&gt;&lt;p&gt;&lt;strong&gt;[root@waf31c ~]# df -hl&lt;/strong&gt;&lt;/p&gt;&lt;pre&gt;Filesystem	Size	Used	Avail	Use%	Mounted on/dev/md2	9.7G	2.3G	6.9G 	25% 	/tmpfs		3.9G	0	3.9G	0%	/dev/shm/dev/md0 	122M 	24M 	92M 	1% 	/boot/dev/md3 	251M 	11M 	228M 	5% 	/meta/dev/md4 	205G 	7.3G 	187G 	4% 	/opt/dev/sda3 	9.5G 	151M 	8.9G 	2% 	/sys-a/dev/sdb3 	9.5G 	151M 	8.9G 	2% 	/sys-btmpfs 		64M 	0 	64M 	0% 	/tmp/ha&lt;p&gt; &lt;/p&gt;&lt;/pre&gt;&lt;p&gt;&lt;strong&gt;[root@waf31c ~]# cat /proc/mdstat&lt;/strong&gt;&lt;/p&gt;&lt;pre&gt;Personalities : [raid1]md0 : active raid1 sdb1[1] sda1[0](F)128448 blocks super 1.0 [2/1] [_U]md4 : active raid1 sdb7[1] sda7[2](F)221222976 blocks [2/1] [_U]md3 : active raid1 sda6[0](F) sdb6[1]264768 blocks super 1.1 [2/1] [_U]md2 : active raid1 sda2[0](F) sdb2[1]10233152 blocks super 1.1 [2/1] [_U]bitmap: 1/1 pages [4KB], 65536KB chunkmd1 : active raid1 sda5[0](F) sdb5[1]2095360 blocks super 1.1 [2/1] [_U]unused devices: &amp;lt;none&amp;gt;&lt;p&gt; &lt;/p&gt;&lt;/pre&gt;&lt;p&gt;&lt;strong&gt;[root@waf31c ~]# ll /dev/disk/by-id&lt;/strong&gt;&lt;/p&gt;&lt;pre&gt;total 0lrwxrwxrwx 1 root root 9 Feb 4 08:46 ata-ST3250310NS_9SF0KLR4 -&amp;gt; ../../sdblrwxrwxrwx 1 root root 10 Feb 4 08:46 ata-ST3250310NS_9SF0KLR4-part1 -&amp;gt; ../../sdb1lrwxrwxrwx 1 root root 10 Feb 4 08:46 ata-ST3250310NS_9SF0KLR4-part2 -&amp;gt; ../../sdb2lrwxrwxrwx 1 root root 10 Feb 4 08:46 ata-ST3250310NS_9SF0KLR4-part3 -&amp;gt; ../../sdb3lrwxrwxrwx 1 root root 10 Feb 4 08:46 ata-ST3250310NS_9SF0KLR4-part4 -&amp;gt; ../../sdb4lrwxrwxrwx 1 root root 10 Feb 4 08:46 ata-ST3250310NS_9SF0KLR4-part5 -&amp;gt; ../../sdb5lrwxrwxrwx 1 root root 10 Feb 4 08:46 ata-ST3250310NS_9SF0KLR4-part6 -&amp;gt; ../../sdb6lrwxrwxrwx 1 root root 10 Feb 4 08:46 ata-ST3250310NS_9SF0KLR4-part7 -&amp;gt; ../../sdb7lrwxrwxrwx 1 root root  9 Feb 4 08:46 ata-ST3250310NS_9SF0MBTX -&amp;gt; ../../sdalrwxrwxrwx 1 root root 10 Feb 4 08:46 ata-ST3250310NS_9SF0MBTX-part1 -&amp;gt; ../../sda1lrwxrwxrwx 1 root root 10 Feb 4 08:46 ata-ST3250310NS_9SF0MBTX-part2 -&amp;gt; ../../sda2lrwxrwxrwx 1 root root 10 Feb 4 08:46 ata-ST3250310NS_9SF0MBTX-part3 -&amp;gt; ../../sda3lrwxrwxrwx 1 root root 10 Feb 4 08:46 ata-ST3250310NS_9SF0MBTX-part4 -&amp;gt; ../../sda4lrwxrwxrwx 1 root root 10 Feb 4 08:46 ata-ST3250310NS_9SF0MBTX-part5 -&amp;gt; ../../sda5lrwxrwxrwx 1 root root 10 Feb 4 08:46 ata-ST3250310NS_9SF0MBTX-part6 -&amp;gt; ../../sda6lrwxrwxrwx 1 root root 10 Feb 4 08:46 ata-ST3250310NS_9SF0MBTX-part7 -&amp;gt; ../../sda7lrwxrwxrwx 1 root root  9 Feb 4 08:46 md-name-waf31c:0 -&amp;gt; ../../md0lrwxrwxrwx 1 root root  9 Feb 4 03:46 md-name-waf31c:1 -&amp;gt; ../../md1lrwxrwxrwx 1 root root  9 Feb 4 08:46 md-name-waf31c:2 -&amp;gt; ../../md2lrwxrwxrwx 1 root root  9 Feb 8 03:00 md-name-waf31c:3 -&amp;gt; ../../md3lrwxrwxrwx 1 root root  9 Feb 4 03:46 md-uuid-12198bbc:3ec91bc8:b2010931:c581b7f6 -&amp;gt; ../../md1lrwxrwxrwx 1 root root  9 Feb 8 03:00 md-uuid-77fd604f:f87dbab6:20a6910c:7918f093 -&amp;gt; ../../md3lrwxrwxrwx 1 root root  9 Feb 4 08:46 md-uuid-84e8994b:f534f554:54f6b785:dc90e134 -&amp;gt; ../../md2lrwxrwxrwx 1 root root  9 Feb 8 03:00 md-uuid-9c7dec9d:176c3fdd:18d80d8f:56da7de0 -&amp;gt; ../../md4lrwxrwxrwx 1 root root  9 Feb 4 08:46 md-uuid-eb30d58f:8af9dca6:2e13a776:ae3e9df8 -&amp;gt; ../../md0lrwxrwxrwx 1 root root  9 Feb 4 08:46 scsi-SATA_ST3250310NS_9SF0KLR4 -&amp;gt; ../../sdblrwxrwxrwx 1 root root 10 Feb 4 08:46 scsi-SATA_ST3250310NS_9SF0KLR4-part1 -&amp;gt; ../../sdb1lrwxrwxrwx 1 root root 10 Feb 4 08:46 scsi-SATA_ST3250310NS_9SF0KLR4-part2 -&amp;gt; ../../sdb2lrwxrwxrwx 1 root root 10 Feb 4 08:46 scsi-SATA_ST3250310NS_9SF0KLR4-part3 -&amp;gt; ../../sdb3lrwxrwxrwx 1 root root 10 Feb 4 08:46 scsi-SATA_ST3250310NS_9SF0KLR4-part4 -&amp;gt; ../../sdb4lrwxrwxrwx 1 root root 10 Feb 4 08:46 scsi-SATA_ST3250310NS_9SF0KLR4-part5 -&amp;gt; ../../sdb5lrwxrwxrwx 1 root root 10 Feb 4 08:46 scsi-SATA_ST3250310NS_9SF0KLR4-part6 -&amp;gt; ../../sdb6lrwxrwxrwx 1 root root 10 Feb 4 08:46 scsi-SATA_ST3250310NS_9SF0KLR4-part7 -&amp;gt; ../../sdb7lrwxrwxrwx 1 root root  9 Feb 4 08:46 scsi-SATA_ST3250310NS_9SF0MBTX -&amp;gt; ../../sdalrwxrwxrwx 1 root root 10 Feb 4 08:46 scsi-SATA_ST3250310NS_9SF0MBTX-part1 -&amp;gt; ../../sda1lrwxrwxrwx 1 root root 10 Feb 4 08:46 scsi-SATA_ST3250310NS_9SF0MBTX-part2 -&amp;gt; ../../sda2lrwxrwxrwx 1 root root 10 Feb 4 08:46 scsi-SATA_ST3250310NS_9SF0MBTX-part3 -&amp;gt; ../../sda3lrwxrwxrwx 1 root root 10 Feb 4 08:46 scsi-SATA_ST3250310NS_9SF0MBTX-part4 -&amp;gt; ../../sda4lrwxrwxrwx 1 root root 10 Feb 4 08:46 scsi-SATA_ST3250310NS_9SF0MBTX-part5 -&amp;gt; ../../sda5lrwxrwxrwx 1 root root 10 Feb 4 08:46 scsi-SATA_ST3250310NS_9SF0MBTX-part6 -&amp;gt; ../../sda6lrwxrwxrwx 1 root root 10 Feb 4 08:46 scsi-SATA_ST3250310NS_9SF0MBTX-part7 -&amp;gt; ../../sda7lrwxrwxrwx 1 root root  9 Feb 4 08:46 wwn-0x5000c5001058e3ca -&amp;gt; ../../sdalrwxrwxrwx 1 root root 10 Feb 4 08:46 wwn-0x5000c5001058e3ca-part1 -&amp;gt; ../../sda1lrwxrwxrwx 1 root root 10 Feb 4 08:46 wwn-0x5000c5001058e3ca-part2 -&amp;gt; ../../sda2lrwxrwxrwx 1 root root 10 Feb 4 08:46 wwn-0x5000c5001058e3ca-part3 -&amp;gt; ../../sda3lrwxrwxrwx 1 root root 10 Feb 4 08:46 wwn-0x5000c5001058e3ca-part4 -&amp;gt; ../../sda4lrwxrwxrwx 1 root root 10 Feb 4 08:46 wwn-0x5000c5001058e3ca-part5 -&amp;gt; ../../sda5lrwxrwxrwx 1 root root 10 Feb 4 08:46 wwn-0x5000c5001058e3ca-part6 -&amp;gt; ../../sda6lrwxrwxrwx 1 root root 10 Feb 4 08:46 wwn-0x5000c5001058e3ca-part7 -&amp;gt; ../../sda7lrwxrwxrwx 1 root root  9 Feb 4 08:46 wwn-0x5000c5001063e3cf -&amp;gt; ../../sdblrwxrwxrwx 1 root root 10 Feb 4 08:46 wwn-0x5000c5001063e3cf-part1 -&amp;gt; ../../sdb1lrwxrwxrwx 1 root root 10 Feb 4 08:46 wwn-0x5000c5001063e3cf-part2 -&amp;gt; ../../sdb2lrwxrwxrwx 1 root root 10 Feb 4 08:46 wwn-0x5000c5001063e3cf-part3 -&amp;gt; ../../sdb3lrwxrwxrwx 1 root root 10 Feb 4 08:46 wwn-0x5000c5001063e3cf-part4 -&amp;gt; ../../sdb4lrwxrwxrwx 1 root root 10 Feb 4 08:46 wwn-0x5000c5001063e3cf-part5 -&amp;gt; ../../sdb5lrwxrwxrwx 1 root root 10 Feb 4 08:46 wwn-0x5000c5001063e3cf-part6 -&amp;gt; ../../sdb6lrwxrwxrwx 1 root root 10 Feb 4 08:46 wwn-0x5000c5001063e3cf-part7 -&amp;gt; ../../sdb7 &lt;/pre&gt;</description><pubDate>Tue, 19 Jan 2016 13:56:28 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>Adding licenses from the console</title><link>https://support.levelblue.com/kb/Goto19593.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WAF/WebDefend 5.x and above &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Need to add or renew licenses &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;All WebDefend appliances must be appropriately licensed. If the WebDefend system includes one or more virtual WebDefend appliances, the system must be activated as well.&lt;/p&gt;&lt;p&gt;Licenses and activation are managed in the License Management window, which can be displayed by selecting the License Management option from the Tools menu.&lt;/p&gt;&lt;p&gt;(&lt;strong&gt;Tools &amp;gt; License Management - load license&lt;/strong&gt;)&lt;/p&gt;&lt;span style="font-size: 11px; line-height: 11px;"&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;p&gt;This information is also found in the Getting Started and Users Guides.&lt;/p&gt;&lt;/span&gt;</description><pubDate>Tue, 19 Jan 2016 13:54:24 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>Where to find WebDefend manuals</title><link>https://support.levelblue.com/kb/Goto19592.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WAF/WebDefend 5.x and above. &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Where can I find the manuals for my installed WebDefend? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Reply:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;If the WebDefend console is installed on a workstation, the manuals can be in the Trustwave console folder. &lt;/li&gt;    &lt;li&gt;The manuals are also installed on the back end server. You can use WinSCP to connect. The path where manuals are stored is &lt;span style="font-family: 'courier new';"&gt;/opt/breach/bwd/installation/console&lt;/span&gt; &lt;/li&gt;&lt;/ul&gt;</description><pubDate>Tue, 19 Jan 2016 13:52:10 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>WebDefend default user names for GUI console and back end</title><link>https://support.levelblue.com/kb/Goto19590.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WAF/WebDefend 5.x &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;What are the default users created on a WebDefend system? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Reply:&lt;/h2&gt;&lt;p&gt;The default Console user is &lt;span style="font-family: 'courier new';"&gt;bgadmin&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Back end users are ha, bus, bgoperator, bgse, and su (root).&lt;/p&gt;&lt;ul&gt;    &lt;li&gt;&lt;span style="font-family: 'courier new';"&gt;ha&lt;/span&gt; - high availability management &lt;/li&gt;    &lt;li&gt;&lt;span style="font-family: 'courier new';"&gt;bus&lt;/span&gt; - upgrade management &lt;/li&gt;    &lt;li&gt;&lt;span style="font-family: 'courier new';"&gt;bgse&lt;/span&gt; - special user - used for ssh login &lt;/li&gt;&lt;/ul&gt;&lt;p&gt; &lt;/p&gt;&lt;h2&gt;&lt;/h2&gt;&lt;p&gt; &lt;/p&gt;</description><pubDate>Tue, 19 Jan 2016 13:50:02 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>Starting and stopping services from the Maintenance menu (bgoperator)</title><link>https://support.levelblue.com/kb/Goto19596.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WAF/WebDefend 5.x and up. &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;How do I stop or start services via the Maintenance tool? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;ol&gt;    &lt;li&gt;Log in to the back end as user &lt;span style="font-family: 'courier new';"&gt;bgoperator&lt;/span&gt;. &lt;/li&gt;    &lt;li&gt;From the Maintenance tool 1 Online Menu &amp;gt; 1 -- WebDefend System Commands Menu &amp;gt;&lt;br /&gt;    &lt;br /&gt;    &lt;div&gt;&lt;br /&gt;    &lt;/div&gt;    &lt;div&gt;From this menu you can stop, start, or restart services.&lt;/div&gt;    &lt;/li&gt;&lt;/ol&gt;&lt;blockquote style="margin-right: 0px;" dir="ltr"&gt;&lt;blockquote style="margin-right: 0px;" dir="ltr"&gt;&lt;p&gt;&lt;span style="font-family: 'courier new';"&gt;------------------------------&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: 'courier new';"&gt;WebDefend System Commands Menu&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: 'courier new';"&gt;------------------------------&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: 'courier new';"&gt;1 -- WebDefend System Status&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: 'courier new';"&gt;2 -- Start WebDefend System&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: 'courier new';"&gt;3 -- Stop WebDefend System&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: 'courier new';"&gt;4 -- Restart WebDefend System&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: 'courier new';"&gt;q -- Return to Previous Menu&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: 'courier new';"&gt;? -- Help&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;p&gt; &lt;/p&gt;&lt;/blockquote&gt;</description><pubDate>Tue, 19 Jan 2016 13:49:16 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>Outlook Web Access and Outlook Anywhere Support </title><link>https://support.levelblue.com/kb/Goto20230.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;All versions of WAF &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;    &lt;p&gt;Do you have any documented guidance for implementing Outlook Web Access or Outlook Anywhere (&lt;em&gt;Outlook installed on a laptop with access over both the LAN and internet&lt;/em&gt;) with the WAF?&lt;/p&gt;    &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WAF can be used with Outlook Web Access (OWA), the website based application. &lt;/li&gt;    &lt;li&gt;WAF does not currently support Outlook Anywhere. Outlook Anywhere uses Microsoft’s RPC over HTTP protocol, which is a very specific protocol that WAF does not currently process. &lt;/li&gt;    &lt;li&gt;Trustwave is investigating adding support for the native Outlook-Exchange Server protocol when the appliance is configured for inline mode. &lt;/li&gt;&lt;/ul&gt;</description><pubDate>Tue, 19 Jan 2016 13:48:58 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>Syslog no longer working after upgrading to 7.0</title><link>https://support.levelblue.com/kb/Goto20229.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WAF 7.0  &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Symptoms:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Syslog server settings have not changed. &lt;/li&gt;    &lt;li&gt;Since upgrading to version 7.0 we see the following error message:&lt;br /&gt;    &lt;span style="font-family: 'courier new';"&gt;Failed to set default Syslog configuration  [1008] - Sending Syslog message failed&lt;/span&gt; &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;p&gt;To resolve this issue:&lt;/p&gt;&lt;ol&gt;    &lt;li&gt;Test whether any alerts are working (such as email alerts). &lt;/li&gt;    &lt;li&gt;Test communication from WAF sensor to syslog server. Use the same protocol as in the site's settings. If it is UDP, check whether the message appears in the syslog server. &lt;/li&gt;&lt;/ol&gt;&lt;h3&gt;Workaround:&lt;/h3&gt;&lt;p&gt;If connection is not successful, create a NAT IP address for the syslog server on the same subnet as the management IP and use that IP address to connect. &lt;/p&gt;&lt;p&gt;The syslog server is actually connected to the same subnet as the bridge IP. Using that IP does not work in version 7.0 (it did work in version 6.2).&lt;/p&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;p&gt;The described behavior is considered a bug. Trustwave plans to correct the problem in a forthcoming release of WAF. &lt;/p&gt;</description><pubDate>Tue, 19 Jan 2016 13:47:49 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>After upgrading to 7.0, Manger drops sensor connectivity</title><link>https://support.levelblue.com/kb/Goto20221.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WebDefend 7.0 &lt;/li&gt;    &lt;li&gt;WebDefend 7.0 SP1 &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;After upgrading to 7.0, we get numerous system events of manger and sensor connectivity lost. &lt;/li&gt;    &lt;li&gt;After upgrading to 7.0, the WebDefend appliance is continuously locking up and requires a physical reboot.  &lt;/li&gt;    &lt;li&gt;There have been no network changes or unusual events.  &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;To verify the issue, log in as root using PuTTY and enter the following command:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: 'courier new';"&gt;cd /opt/breach/bwd/logs&lt;/span&gt;&lt;/p&gt;&lt;p&gt;If you see numerous coredumps here this is likely to be due to a known issue with these versions.&lt;/p&gt;&lt;p&gt;The issue is that the online updates and reputation services cause WebDefend (7.0 or 70. SP1) to drop services. This can result in the appliance becoming unresponsive and requiring a physical reboot. &lt;/p&gt;&lt;h2&gt;Resolution:&lt;/h2&gt;&lt;p&gt;This issue is resolved by upgrading to version 7.0 SP2 and applying HF2. &lt;/p&gt;</description><pubDate>Tue, 19 Jan 2016 13:46:59 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>Importing an export (restoring from backup)</title><link>https://support.levelblue.com/kb/Goto19603.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WAF 5.x and above. &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;How can I import backup configuration and data? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;You perform the import using the Maintenance tool in bgoperator.&lt;/p&gt;&lt;ol&gt;    &lt;li&gt;Use WinSCP to copy the backup to user bgse. The files will be in &lt;span style="font-family: 'courier new';"&gt;/home/bgse/pub&lt;/span&gt;    &lt;ul&gt;        &lt;li&gt;For a standalone installation, copy both manager and sensor backups.  &lt;/li&gt;        &lt;li&gt;For a manager only the manager backup is required. &lt;/li&gt;        &lt;li&gt;For a sensor only the sensor backup is required. &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;    &lt;li&gt;Once you have copied the backups to the /pub file, run bgoperator. &lt;/li&gt;    &lt;li&gt;Select  &lt;strong&gt;2&lt;/strong&gt; offline menu, then&lt;strong&gt; 2&lt;/strong&gt; Import Export menu. &lt;/li&gt;    &lt;li&gt;You will be asked to enter the file(s) paths. Enter these as absolute paths, for instance, &lt;span style="font-family: 'courier new';"&gt;/home/bgse/pub/managerbackup.tgz&lt;/span&gt; &lt;/li&gt;&lt;/ol&gt;&lt;blockquote style="margin-right: 0px;" dir="ltr"&gt;&lt;pre&gt;---------Main Menu---------1 -- Online Menu2 -- Offline Menu3 -- System Menu? -- Help[1]&amp;gt;2 ------------Offline Menu------------1 -- Configuration Menu2 -- Import - Export Menu3 -- System Events Menu4 -- DB maintenance Menu5 -- License Management Menu6 -- Audit Log Menuq -- Return to Previous Menu? -- Help&lt;/pre&gt;&lt;/blockquote&gt;</description><pubDate>Tue, 15 Dec 2015 13:08:58 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>Disabling SSLv3 to mitigate the CVE-2014-3566 (Poodle) vulnerability</title><link>https://support.levelblue.com/kb/Goto20114.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WebDefend 7.0 or higher &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;How can I disable SSLv3 on WebDefend? &lt;/li&gt;    &lt;li&gt;How can I correct WebDefend configuration to protect against CVE-2014-3566 (Poodle)? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This procedure applies only to Inline deployments and is not valid for management traffic.&lt;/p&gt;&lt;h3&gt;For WebDefend version 7.0 and up:&lt;/h3&gt;&lt;ol&gt;    &lt;li&gt;Log in to the active node via SSH as bgse &lt;/li&gt;    &lt;li&gt;Switch to root:&lt;br /&gt;    &lt;br /&gt;    &lt;span style="font-family: 'courier new';"&gt;# su -&lt;/span&gt;&lt;/li&gt;    &lt;li&gt;Stop WebDefend services.&lt;br /&gt;    &lt;br /&gt;    &lt;span style="font-family: 'courier new';"&gt;# service all_services_init stop&lt;/span&gt;&lt;/li&gt;    &lt;li&gt;Back up the existing gsp.conf file&lt;br /&gt;    &lt;span style="font-family: 'courier new';"&gt; &lt;br /&gt;    # cp -p /opt/breach/bwd/conf/gsp.conf /opt/breach/bwd/conf/gsp.conf.ssl&lt;/span&gt;&lt;/li&gt;    &lt;li&gt;Edit the gsp.conf file:&lt;br /&gt;    &lt;br /&gt;    &lt;span style="font-family: 'courier new';"&gt;# vi /opt/breach/bwd/conf/gsp.conf&lt;/span&gt;&lt;/li&gt;    &lt;li&gt;Add the following line in the &lt;span style="font-family: 'courier new';"&gt;[GSP_GENERAL]&lt;/span&gt; section:&lt;br /&gt;    &lt;br /&gt;    &lt;span style="font-family: 'courier new';"&gt;IL_DEFAULT_SSL_PROTOCOL = TLSv1|TLSv1.1|TLSv1.2&lt;br /&gt;    &lt;/span&gt; &lt;br /&gt;    For example, change:&lt;br /&gt;    &lt;br /&gt;    &lt;span style="font-family: 'courier new';"&gt;[GSP_GENERAL]&lt;br /&gt;    GSP_NAME = TEST&lt;/span&gt;&lt;br /&gt;    &lt;br /&gt;    &lt;br /&gt;    to:&lt;br /&gt;    &lt;br /&gt;    &lt;br /&gt;    &lt;span style="font-family: 'courier new';"&gt;[GSP_GENERAL]&lt;br /&gt;    GSP_NAME = TEST&lt;br /&gt;    IL_DEFAULT_SSL_PROTOCOL = TLSv1|TLSv1.1|TLSv1.2&lt;/span&gt;&lt;/li&gt;    &lt;li&gt;Save the file &lt;/li&gt;    &lt;li&gt;Start WebDefend services:&lt;br /&gt;    &lt;br /&gt;    &lt;span style="font-family: 'courier new';"&gt;# service all_services_init start&lt;/span&gt; &lt;/li&gt;&lt;/ol&gt;&lt;h3&gt;For other versions of WebDefend: &lt;/h3&gt;In point 6 of the above&lt;ul&gt;    &lt;li&gt;procedure, do not set &lt;span style="font-family: 'courier new';"&gt;IL_DEFAULT_SSL_PROTOCOL    &lt;/span&gt;&lt;/li&gt;    &lt;li&gt;&lt;/li&gt;    &lt;li&gt;&lt;/li&gt;    &lt;li&gt;&lt;/li&gt;    &lt;li&gt;Instead, for each site add the following lines in gsp.conf&lt;br /&gt;    &lt;br /&gt;    &lt;span style="font-family: 'courier new';"&gt;IL_CLIENT_SSL_PROTOCOLS= TLSv1|TLSv1.1|TLSv1.2&lt;br /&gt;    IL_SERVER_SSL_PROTOCOLS= TLSv1|TLSv1.1|TLSv1.2&lt;/span&gt;&lt;span style="font-size: 10.5pt; font-family: arial, sans-serif; color: #333333;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style="font-size: 10.5pt; font-family: arial, sans-serif; color: #333333;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt; &lt;span style="font-size: 10.5pt; font-family: arial, sans-serif; color: #333333;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;</description><pubDate>Tue, 15 Dec 2015 13:07:00 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>Disabling SSLv3 and RC4 ciphers in Inline deployment</title><link>https://support.levelblue.com/kb/Goto20374.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WebDefend 7.1 or higher &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;How can I disable SSLv3 and RC4 ciphers in inline deployment? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;ol&gt;    &lt;li&gt;Log in to the active node via SSH as bgse &lt;/li&gt;    &lt;li&gt;Switch to root:&lt;br /&gt;     &lt;br /&gt;    &lt;span style="font-family: courier new;"&gt;# su -&lt;/span&gt;&lt;br /&gt;      &lt;/li&gt;    &lt;li&gt;Stop WebDefend services:&lt;br /&gt;     &lt;br /&gt;    &lt;span style="font-family: courier new;"&gt;# service all_services_init stop&lt;br /&gt;    &lt;/span&gt;  &lt;/li&gt;    &lt;li&gt;Back up the existing gsp.conf file.&lt;br /&gt;     &lt;br /&gt;    &lt;span style="font-family: courier new;"&gt;# cp -p /opt/breach/bwd/conf/gsp.conf /opt/breach/bwd/conf/gsp.conf.ssl&lt;br /&gt;    &lt;/span&gt;  &lt;/li&gt;    &lt;li&gt;Check your current configuration:&lt;br /&gt;     &lt;br /&gt;    &lt;span style="font-family: courier new;"&gt;# grep IL_ /opt/breach/bwd/conf/gsp.conf&lt;/span&gt;&lt;br /&gt;      &lt;/li&gt;    &lt;li&gt;If in the output you see entries starting with &lt;span style="font-family: courier new;"&gt;IL_CLIENT_SSL_CIPHERS&lt;/span&gt; or &lt;span style="font-family: courier new;"&gt;IL_SERVER_SSL_CIPHERS&lt;/span&gt;    &lt;ul&gt;        &lt;li&gt;Remove the lines starting with &lt;span style="font-family: courier new;"&gt;IL_CLIENT_SSL_CIPHERS&lt;/span&gt; and &lt;span style="font-family: courier new;"&gt;IL_SERVER_SSL_CIPHERS&lt;/span&gt; from the &lt;span style="font-family: courier new;"&gt;gsp.conf&lt;/span&gt; file. &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;    &lt;li&gt;If in the output you see entries starting with &lt;span style="font-family: courier new;"&gt;IL_DEFAULT_SSL_PROTOCOL&lt;/span&gt; and &lt;span style="font-family: courier new;"&gt;IL_DEFAULT_SSL_CIPHERS &lt;/span&gt;    &lt;ul&gt;        &lt;li&gt;See the steps below and edit the lines in the &lt;span style="font-family: courier new;"&gt;gsp.conf&lt;/span&gt; file to match the information shown. &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;    &lt;li&gt;Edit the &lt;span style="font-family: courier new;"&gt;gsp.conf&lt;/span&gt; file:&lt;br /&gt;     &lt;br /&gt;    &lt;span style="font-family: courier new;"&gt;# vi /opt/breach/bwd/conf/gsp.conf&lt;/span&gt;&lt;br /&gt;      &lt;/li&gt;    &lt;li&gt;Add the following lines in the &lt;span style="font-family: courier new;"&gt;[GSP_GENERAL]&lt;/span&gt; section:&lt;br /&gt;    &lt;br /&gt;    &lt;pre&gt;IL_DEFAULT_SSL_PROTOCOL = TLSv1|TLSv1.1|TLSv1.2IL_DEFAULT_SSL_CIPHERS = EECDH+aRSA+AES:+aRSA+CBC:+aRSA+AES256:EECDH+aRSA+3DES:RSA+3DES:RSA+AES:!SSLv2:!EXPORT:!LOW&lt;/pre&gt;    For example change:    &lt;pre&gt;[GSP_GENERAL]GSP_NAME = TEST&lt;/pre&gt;    to:&lt;br /&gt;    &lt;pre&gt;[GSP_GENERAL]GSP_NAME = TESTIL_DEFAULT_SSL_PROTOCOL = TLSv1|TLSv1.1|TLSv1.2IL_DEFAULT_SSL_CIPHERS = EECDH+aRSA+AES:+aRSA+CBC:+aRSA+AES256:EECDH+aRSA+3DES:RSA+3DES:RSA+AES:!SSLv2:!EXPORT:!LOW&lt;/pre&gt;    &lt;/li&gt;    &lt;li&gt;Save the file and start webdefend services: &lt;br /&gt;     &lt;br /&gt;    # service all_services_init start &lt;/li&gt;&lt;/ol&gt;If you notice any problems with starting services after making the changes above, revert the changes&lt;br /&gt;&lt;pre&gt;# service all_services_init stop# cp -p /opt/breach/bwd/conf/gsp.conf.ssl /opt/breach/bwd/conf/gsp.conf# service all_services_init start&lt;/pre&gt;&lt;p&gt; &lt;/p&gt;</description><pubDate>Fri, 11 Sep 2015 05:29:17 GMT</pubDate><dc:creator>Piotr Dłubisz</dc:creator></item><item><title>Do hotfixes have to be applied to both Sensors in a High Availability pair?</title><link>https://support.levelblue.com/kb/Goto20387.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WAF 7.0 &lt;/li&gt;    &lt;li&gt;WAF 7.1 &lt;/li&gt;    &lt;li&gt;WAF 7.5 &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;    &lt;p&gt;Do hotfixes have to be applied to both Sensors in a High Availability (HA) pair?&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;    &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Reply:&lt;/h2&gt;&lt;p&gt;In most cases you do not have to take special action in a HA environment. &lt;/p&gt;&lt;p&gt;The hotfixes normally reside in the &lt;span style="font-family: 'courier new';"&gt;opt&lt;/span&gt; partition. In this case, when you apply them to the Active Sensor, they will automatically apply to the other Sensor when the WAF fails over. &lt;/p&gt;&lt;h2&gt;&lt;/h2&gt;</description><pubDate>Wed, 09 Sep 2015 17:06:24 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>Configuring WAF to use | as delimiter instead of &lt;PIPE&gt; in syslog messages</title><link>https://support.levelblue.com/kb/Goto20354.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WebDefend (WAF) 7.1 or higher &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;How can I configure WAF to use | as delimiter instead of the text &amp;lt;PIPE&amp;gt; in syslog messages? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;ol&gt;    &lt;li&gt;Log in to WebDefend via ssh as bgse user. &lt;/li&gt;    &lt;li&gt;Switch to root:&lt;br /&gt;     &lt;br /&gt;    &lt;span style="font-family: courier new;"&gt;# su -&lt;/span&gt;&lt;br /&gt;      &lt;/li&gt;    &lt;li&gt;Stop WebDefend services:&lt;br /&gt;     &lt;br /&gt;    &lt;span style="font-family: courier new;"&gt;# service all_services_init stop&lt;/span&gt;&lt;br /&gt;      &lt;/li&gt;    &lt;li&gt;Make a backup of the gsp.conf file:&lt;br /&gt;     &lt;br /&gt;    &lt;span style="font-family: courier new;"&gt;# cp -p /opt/breach/bwd/conf/gsp.conf /opt/breach/bwd/conf/gsp.conf.pipe&lt;/span&gt;&lt;br /&gt;      &lt;/li&gt;    &lt;li&gt;Edit the gsp.conf file:&lt;br /&gt;     &lt;br /&gt;    &lt;span style="font-family: courier new;"&gt;# vi /opt/breach/bwd/conf/gsp.conf&lt;/span&gt;&lt;br /&gt;      &lt;/li&gt;    &lt;li&gt;Add the following line in the &lt;span style="font-family: courier new;"&gt;[GSP_GENERAL]&lt;/span&gt; section:&lt;br /&gt;     &lt;br /&gt;    &lt;span style="font-family: courier new;"&gt;SYSLOG_PIPE_ESCAPING = false&lt;/span&gt;&lt;br /&gt;     &lt;br /&gt;    The section should appear similar to the following (depending on other settings):&lt;br /&gt;    &lt;span style="font-family: courier new;"&gt; &lt;br /&gt;    [GSP_GENERAL]&lt;br /&gt;    GSP_NAME = TEST&lt;br /&gt;    IL_DEFAULT_SSL_PROTOCOL = TLSv1|TLSv1.1|TLSv1.2&lt;br /&gt;    SYSLOG_PIPE_ESCAPING = false&lt;br /&gt;    &lt;/span&gt;  &lt;/li&gt;    &lt;li&gt;Start WebDefend services:&lt;br /&gt;     &lt;br /&gt;    &lt;span style="font-family: courier new;"&gt;# service all_services_init start&lt;/span&gt; &lt;/li&gt;&lt;/ol&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Example log line before the change:&lt;/strong&gt;&lt;/p&gt;&lt;pre&gt;Jul 21 14:23:25 10.92.208.197 Jul 21 07:00:01 10.92.208.197 TRUSTWAVE_WAF&amp;lt;PIPE&amp;gt;Name:System command injection - Pattern: [cmd.exe]&amp;lt;PIPE&amp;gt;Result_CAT:Attempt&amp;lt;PIPE&amp;gt;Severity:5&amp;lt;PIPE&amp;gt;Source:10.244.1.166&amp;lt;PIPE&amp;gt;Country:N/A&amp;lt;PIPE&amp;gt;Country_ID:--&amp;lt;PIPE&amp;gt;Site:WWW.WARSAW.LOCAL&amp;lt;PIPE&amp;gt;Host:www.warsaw.local&amp;lt;PIPE&amp;gt;URL:/&amp;lt;PIPE&amp;gt;Method:POST&amp;lt;PIPE&amp;gt;Query: &amp;lt;PIPE&amp;gt;Status:200&amp;lt;PIPE&amp;gt;Entry_Type:58823&amp;lt;PIPE&amp;gt;Exit_Type:0&amp;lt;PIPE&amp;gt;Exit_Event: &amp;lt;PIPE&amp;gt;&lt;/pre&gt;&lt;p&gt;&lt;strong&gt;&lt;br /&gt;Example log line after the change:&lt;/strong&gt;&lt;/p&gt;&lt;pre&gt;Jul 21 16:29:41 10.92.208.197 Jul 21 09:06:18 10.92.208.197 TRUSTWAVE_WAF|Name:System command injection - Pattern: [cmd.exe]|Result_CAT:Attempt|Severity:5|Source:10.244.1.166|Country:N/A|Country_ID:--|Site:WWW.WARSAW.LOCAL|Host:www.warsaw.local|URL:/|Method:POST|Query: |Status:200|Entry_Type:58823|Exit_Type:0|Exit_Event: |&lt;/pre&gt;</description><pubDate>Thu, 23 Jul 2015 03:01:05 GMT</pubDate><dc:creator>Piotr Dłubisz</dc:creator></item><item><title>Configuring multiple reverse proxy IPs in Amazon Machine Images (AMI)</title><link>https://support.levelblue.com/kb/Goto20210.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WAF 7 SP1 &lt;/li&gt;    &lt;li&gt;WAF 7.1 &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;What are the steps for the initial configuration for a Manager and a Sensor?  &lt;/li&gt;    &lt;li&gt;Where do I set the management IP? &lt;/li&gt;    &lt;li&gt;How can I configure MULTIPLE reverse proxy IPs in Amazon Machine Images (AMI)? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;p&gt;When you configure the NICs for the WAF, you create ENIs (Elastic network interfaces).&lt;/p&gt;&lt;p&gt;One ENI is required for &lt;strong&gt;management &lt;/strong&gt;and &lt;span style="text-decoration: underline;"&gt;at least&lt;/span&gt; one ENI for Web traffic.&lt;/p&gt;&lt;p&gt;Each ENI can hold multiple secondary private IP addresses.&lt;/p&gt;&lt;p&gt;The number of ENIs per instance and max number of private IP addresses per ENI depends on the instance type and can be found in Amazon documentation:&lt;/p&gt;&lt;ul&gt;    &lt;li&gt;&lt;a href="https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-eni.html#AvailableIpPerENI" class="ApplyClass" target="_blank"&gt;Private IP Addresses Per ENI Per Instance Type&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Each ENI private IP address can be linked to an Elastic IP address (public IP). More details in Amazon documentation:&lt;/p&gt;&lt;ul&gt;    &lt;li&gt;&lt;a href="https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/MultipleIP.html#StepThreeEIP" target="_blank"&gt;Associating an Elastic IP Address with the Secondary Private IP Address&lt;/a&gt;. &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Remember that when you define a site at the WAF console, you always use the private IP addresses. &lt;/p&gt;&lt;p&gt;The WAF is not aware of the site's public IP addresses.&lt;/p&gt;&lt;h3&gt;Assigning a secondary private IP address&lt;/h3&gt;&lt;div&gt;&lt;div&gt;To assign a secondary private IP address when launching an instance in EC2-VPC (Note: these instructions are taken from Amazon documentation on &lt;a href="http://docs.aws.amazon.com/AWSEC2/latest/UserGuide/MultipleIP.html" target="_blank"&gt;Multiple Private IP Addresses&lt;/a&gt;)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;ol&gt;    &lt;li&gt;    &lt;div&gt;Open the Amazon EC2 console.&lt;/div&gt;    &lt;/li&gt;    &lt;li&gt;    &lt;div&gt;&lt;span style="line-height: 11px;"&gt;Click the &lt;strong&gt;Launch Instance&lt;/strong&gt; button.&lt;/span&gt;&lt;/div&gt;    &lt;/li&gt;    &lt;li&gt;    &lt;div&gt;&lt;span style="line-height: 11px;"&gt;Choose an AMI and click its &lt;strong&gt;Select&lt;/strong&gt; button, then choose an instance type and click &lt;strong&gt;Next: Configure Instance Details&lt;/strong&gt;.&lt;/span&gt;&lt;/div&gt;    &lt;/li&gt;    &lt;li&gt;    &lt;div&gt;&lt;span style="line-height: 11px;"&gt;On the Configure Instance Details page, choose a VPC from the Network list, and a subnet from the Subnet list.&lt;/span&gt;&lt;/div&gt;    &lt;/li&gt;    &lt;li&gt;    &lt;div&gt;&lt;span style="line-height: 11px;"&gt;In the Network Interfaces section, c&lt;/span&gt;lick &lt;strong&gt;Add Device&lt;/strong&gt; to add another network interface. The console enables you specify up to 2 network interfaces when you launch an instance. &lt;/div&gt;    &lt;ol style="list-style-type: lower-alpha;"&gt;        &lt;li&gt;        &lt;div&gt;After you launch the instance, click &lt;strong&gt;Network Interfaces&lt;/strong&gt; in the navigation pane to add additional &lt;span class="Apple-tab-span" style="white-space: pre;"&gt;&lt;/span&gt;network interfaces. The total number of network interfaces that you can attach varies by instance type. For more information, see &lt;a href="https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-eni.html#AvailableIpPerENI" class="ApplyClass" target="_blank"&gt;Private IP Addresses Per ENI Per Instance Type&lt;/a&gt;.&lt;/div&gt;        &lt;/li&gt;        &lt;li&gt;        &lt;div&gt;For each network interface, you can specify a primary private IP address, and one or more secondary private IP addresses. Normally, accept the IP address that is automatically assigned.&lt;/div&gt;        &lt;/li&gt;        &lt;li&gt;        &lt;div&gt;Under Secondary IP addresses, click &lt;strong&gt;Add IP&lt;/strong&gt;, and then enter a private IP address in the subnet range, or accept the default, Auto-assign.&lt;/div&gt;        &lt;ul&gt;            &lt;li&gt;            &lt;div&gt;&lt;em&gt;Important: &lt;/em&gt;After you have added a secondary private IP address to a network interface, you must connect to the instance and configure the secondary private IP address on the instance itself. For more information, see &lt;a href="http://docs.aws.amazon.com/AWSEC2/latest/UserGuide/MultipleIP.html#StepTwoConfigOS" target="_blank"&gt;Configuring the Operating &lt;span class="Apple-tab-span" style="white-space: pre;"&gt;&lt;/span&gt;System on Your Instance to Recognize the Secondary Private IP Address&lt;/a&gt;.&lt;/div&gt;            &lt;/li&gt;        &lt;/ul&gt;        &lt;/li&gt;        &lt;li&gt;        &lt;div&gt;Click &lt;strong&gt;Next: Add Storage&lt;/strong&gt;.&lt;/div&gt;        &lt;/li&gt;    &lt;/ol&gt;    &lt;/li&gt;    &lt;li&gt;    &lt;div&gt;On the &lt;strong&gt;Add Storage&lt;/strong&gt; page, you can specify volumes to attach to the instance in addition to the volumes specified by the AMI (such as the root device volume), and then click &lt;strong&gt;Next: Tag Instance&lt;/strong&gt;.&lt;/div&gt;    &lt;/li&gt;    &lt;li&gt;    &lt;div&gt;On the Tag Instance page, specify tags for the instance, such as a user-friendly name, and then click &lt;strong&gt;Next: Configure Security Group&lt;/strong&gt;.&lt;/div&gt;    &lt;/li&gt;    &lt;li&gt;    &lt;div&gt;&lt;span style="line-height: 11px;"&gt;On the Configure Security Group page, select an existing security group or create a new one. Click &lt;strong&gt;Review and Launch&lt;/strong&gt;.&lt;/span&gt;&lt;/div&gt;    &lt;/li&gt;    &lt;li&gt;    &lt;div&gt;&lt;span style="line-height: 11px;"&gt;On the Review Instance Launch page, review your settings, and then click &lt;strong&gt;Launch&lt;/strong&gt; to choose a key pair and launch your instance. If you do not have any existing EC2 key pairs, the wizard prompts you to create one.&lt;/span&gt;&lt;/div&gt;    &lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;&lt;h2&gt;&lt;/h2&gt;&lt;h2&gt;&lt;/h2&gt;</description><pubDate>Mon, 01 Jun 2015 12:46:17 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item></channel></rss>