Handling multiple clients with modsecurity

Blason R <[email protected]> Mon, 8 Mar 2021 12:29:05 +0530
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <CAPPXLT_B5pkYZZ3h+vEHkXetpaAu=ErtLUcO7vfxWX6bLPHH=Q@mail.gmail.com>
Hi Folks,

Here is my requirement and seeking any heads up from community -

   - I already have nginx server running for our multiple customers in
   reverse proxy mode
   - So Nginx reverse proxy is sending requests to customer web servers
   - lets say -


   - Customer-1 exmaple.com -> web site example.com
   - Customer-2 www.test.com -. www.test.com
   - Customer3-  acme.com -> www.acme.com


   - Now I am trying to integrate modsecurity with Nginx
   - So my question is - Do I need to create a separate config file for
   every customer location?
   - like /etc/nginx/modsec/example.com/main.conf

/etc/nginx/modsec/example.com/modsecurity.conf
/etc/nginx/modsec/example.com/coreruleset/rules/*.conf
/etc/nginx/modsec/example.com/coreruleset/cor-ruleset.conf
##################
/etc/nginx/modsec/test.com/main.conf
/etc/nginx/modsec/test.com/modsecurity.conf
/etc/nginx/modsec/test.com/coreruleset/rules/*.conf
/etc/nginx/modsec/test.com/coreruleset/cor-ruleset.conf
##################
/etc/nginx/modsec/acme.com/main.conf
/etc/nginx/modsec/acme.com/modsecurity.conf
/etc/nginx/modsec/acme.com/coreruleset/rules/*.conf
/etc/nginx/modsec/acme.com/coreruleset/cor-ruleset.conf

   - Is this correct method to manage
   rules/exceptions/blacklisting/whitelisting for multiple customers? Or is
   there any other alternative?
   - Plus logs should be separate for every customer which I am thinking to
   generate in json file


   - Please let me know if this is the correct option considering around
   15-20 sites protected by nginx and customers.


   - SecAuditEngine RelevantOnly
   - SecAuditLogRelevantStatus "^(?:5|4(?!04))"


   - SecAuditLogParts ABIJDEFHZ
   - SecAuditLogFormat JSON
   - SecAuditLog /var/log/modsec_audit.log

TIA
Blason R

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/