Handling multiple clients with modsecurity
Blason R <[email protected]> Mon, 8 Mar 2021 12:29:05 +0530
| Newsgroups | gmane.comp.apache.mod-security.user |
|---|---|
| Message-ID | <CAPPXLT_B5pkYZZ3h+vEHkXetpaAu=ErtLUcO7vfxWX6bLPHH=Q@mail.gmail.com> |
Hi Folks, Here is my requirement and seeking any heads up from community - - I already have nginx server running for our multiple customers in reverse proxy mode - So Nginx reverse proxy is sending requests to customer web servers - lets say - - Customer-1 exmaple.com -> web site example.com - Customer-2 www.test.com -. www.test.com - Customer3- acme.com -> www.acme.com - Now I am trying to integrate modsecurity with Nginx - So my question is - Do I need to create a separate config file for every customer location? - like /etc/nginx/modsec/example.com/main.conf /etc/nginx/modsec/example.com/modsecurity.conf /etc/nginx/modsec/example.com/coreruleset/rules/*.conf /etc/nginx/modsec/example.com/coreruleset/cor-ruleset.conf ################## /etc/nginx/modsec/test.com/main.conf /etc/nginx/modsec/test.com/modsecurity.conf /etc/nginx/modsec/test.com/coreruleset/rules/*.conf /etc/nginx/modsec/test.com/coreruleset/cor-ruleset.conf ################## /etc/nginx/modsec/acme.com/main.conf /etc/nginx/modsec/acme.com/modsecurity.conf /etc/nginx/modsec/acme.com/coreruleset/rules/*.conf /etc/nginx/modsec/acme.com/coreruleset/cor-ruleset.conf - Is this correct method to manage rules/exceptions/blacklisting/whitelisting for multiple customers? Or is there any other alternative? - Plus logs should be separate for every customer which I am thinking to generate in json file - Please let me know if this is the correct option considering around 15-20 sites protected by nginx and customers. - SecAuditEngine RelevantOnly - SecAuditLogRelevantStatus "^(?:5|4(?!04))" - SecAuditLogParts ABIJDEFHZ - SecAuditLogFormat JSON - SecAuditLog /var/log/modsec_audit.log TIA Blason R _______________________________________________ mod-security-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/mod-security-users Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: http://www.modsecurity.org/projects/commercial/rules/ http://www.modsecurity.org/projects/commercial/support/