Re: Akamai WAF
"David Edelman" <[email protected]> Sun, 21 Oct 2018 10:33:48 -0400
| Newsgroups | gmane.network.argus |
|---|---|
| Message-ID | <[email protected]> |
This is a multipart message in MIME format. ------=_NextPart_000_0001_01D46929.8DF16490 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable -----BEGIN PGP SIGNED MESSAGE-----=20 Hash: SHA1=20 Ah, the joys of Akamai WAF and True-Client-IP (instead of = X-Forwarded-For)=20 =20 Since this is a request header, it is going to be in the source user = data and it will be encrypted for all https traffic between the Akamai = edge and what Akamai calls the origin (your web server.) For http = traffic, it will be available and you might want to try a simple = experiment to verify its presence. =20 Change the ratop to plain ra and verify that you can see the request = header. Make sure to change the duser:2048 to suser:2048 so that you are = seeing the right buffer contents. It sometimes is easier to read if you = add -M printer=3Dhex to the command line argument string. =20 If you see the request header, I anticipate that you will for the http = traffic, you can move to ratop (drop the -M printer=3Dhex) and while it = is running hit the =E2=80=98:=E2=80=99 to get the command line. I = believe that if you type =E2=80=98s=E2=80=99 you will see the list of = fields being displayed and the width arguments if any. You can edit = these values and hit enter to enable the change. I=E2=80=99m not sure = that the field widths are always transferred to ratop from the command = line and I can=E2=80=99t test that where I am. =20 - --Dave=20 =20 Dave Edelman=20 =20 From: Argus-info = <[email protected]> On Behalf = Of Monah Baki=20 Sent: Thursday, October 18, 2018 9:09 AM=20 To: Eric Kinzie <[email protected]>=20 Cc: Argus <[email protected]>=20 Subject: Re: [ARGUS] Akamai WAF=20 =20 Hi Eric,=20 =20 I bumped the ARGUS_CAPTURE_DATA_LEN value to 2048, so running ratop -S = localhost:561 -s trans stime saddr:40 sport sco daddr dport dco suser = duser:2048, I can't see the rest of the duser column, gets chopped off, = probably displays 50 characters only (small monitor). Is there a way to = overcome this? =20 Thanks=20 Monah=20 =20 On Thu, Oct 18, 2018 at 8:47 AM Eric Kinzie <[email protected] = <mailto:[email protected]> > wrote:=20 On October 17, 2018 12:47:43 PM EDT, Monah Baki = <[email protected] <mailto:[email protected]> > wrote:=20 >Hi all,=20 >=20 >We are using akamai WAF services to protect our webserver. = Currently=20 >running the latest argus/client on the webserver. When running = ratop,=20 >the=20 >SrcAddr shows only the akamai IP=20 >(a23-212-3-119.deploy.static.akamaitechn*)=20 >hitting our webserver.=20 >Akamai confirmed True-Client-IP is enabled and we should be = able to see=20 >the=20 >real IP in the request header. Can I get this info when using = ratop?=20 >=20 >=20 >Trans StartTime = SrcAddr=20 >Sport=20 >sCo DstAddr Dport dCo = srcUdata=20 > dstUdata=20 > 14 12:42:39.209029 = a23-212-3-119.deploy.static.akamaitechn*.49057=20 > US www.ntis.gov.https <http://www.ntis.gov.https> ZZ=20 >s[50]=3D............s~V-...Tl....x..`...<.#.4^.+..a ..+...=20 >d[50]=3D....Y...U..[.f...=3D...|.I....:.t..?..:Yc...& O.-G].=20 > 2 12:45:50.752456 = a23-212-53-84.deploy.static.akamaitechn*.61219=20 > US www.ntis.gov.https <http://www.ntis.gov.https> ZZ=20 >s[50]=3D...........g.....E{.K.:S.4..4.e.F_..^.A."Rx o#Rr&3=20 >d[50]=3D....Q...M..[.g>.....*..... ....G.as.V..y..d o#Rr&3=20 >=20 >=20 >Thanks=20 >Monah=20 =20 Since this value is in the http headers and, in this case, https = is used you will not be able to see the address in the Argus user = buffers. For non-encrypted http, set the ARGUS_CAPTURE_DATA_LEN to = something large enough to get all of the http headers and then the duser = column in ratop should show what you want. -----BEGIN PGP SIGNATURE-----=20 iF0EARECAB0WIQQP+UHquEepll566aqXCCyZOY1FIQUCW8yOQgAKCRCXCCyZOY1F=20 IfgdAJ9kn76NjN9FMc8PsYulqX7s3Z5pFQCffeFLqP2zaRxGzCaortLyHrq5CDY=3D=20 =3DWPxX=20 -----END PGP SIGNATURE-----=20 ------=_NextPart_000_0001_01D46929.8DF16490 Content-Type: text/html; charset="utf-8" Content-Transfer-Encoding: quoted-printable <html xmlns:v=3D"urn:schemas-microsoft-com:vml" = xmlns:o=3D"urn:schemas-microsoft-com:office:office" = xmlns:w=3D"urn:schemas-microsoft-com:office:word" = xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" = xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta = http-equiv=3DContent-Type content=3D"text/html; charset=3Dutf-8"><meta = name=3DGenerator content=3D"Microsoft Word 15 (filtered = medium)"><style><!-- /* Font Definitions */ @font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4;} @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0in; margin-bottom:.0001pt; font-size:11.0pt; font-family:"Calibri",sans-serif;} a:link, span.MsoHyperlink {mso-style-priority:99; color:blue; text-decoration:underline;} a:visited, span.MsoHyperlinkFollowed {mso-style-priority:99; color:purple; text-decoration:underline;} p.msonormal0, li.msonormal0, div.msonormal0 {mso-style-name:msonormal; mso-margin-top-alt:auto; margin-right:0in; mso-margin-bottom-alt:auto; margin-left:0in; font-size:11.0pt; font-family:"Calibri",sans-serif;} span.EmailStyle19 {mso-style-type:personal-compose;} .MsoChpDefault {mso-style-type:export-only; font-size:10.0pt;} @page WordSection1 {size:8.5in 11.0in; margin:1.0in 1.0in 1.0in 1.0in;} div.WordSection1 {page:WordSection1;} --></style><!--[if gte mso 9]><xml> <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" /> </xml><![endif]--><!--[if gte mso 9]><xml> <o:shapelayout v:ext=3D"edit"> <o:idmap v:ext=3D"edit" data=3D"1" /> </o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue = vlink=3Dpurple><div class=3DWordSection1><p>-----BEGIN PGP SIGNED = MESSAGE----- <br>Hash: SHA1 <o:p></o:p></p><p>Ah, the joys of Akamai WAF = and True-Client-IP (instead of X-Forwarded-For) <o:p></o:p></p><p> = <o:p></o:p></p><p>Since this is a request header, it is going to be in = the source user data and it will be encrypted for all https traffic = between the Akamai edge and what Akamai calls the origin (your web = server.) For http traffic, it will be available and you might want to = try a simple experiment to verify its presence.<o:p></o:p></p><p> = <o:p></o:p></p><p>Change the ratop to plain ra and verify that you can = see the request header. Make sure to change the duser:2048 to suser:2048 = so that you are seeing the right buffer contents. It sometimes is easier = to read if you add -M printer=3Dhex to the command line argument = string.<o:p></o:p></p><p> <o:p></o:p></p><p>If you see the request = header, I anticipate that you will for the http traffic, you can move to = ratop (drop the -M printer=3Dhex) and while it is running hit the = =E2=80=98:=E2=80=99 to get the command line. I believe that if you type = =E2=80=98s=E2=80=99 you will see the list of fields being displayed and = the width arguments if any. You can edit these values and hit enter to = enable the change. I=E2=80=99m not sure that the field widths are always = transferred to ratop from the command line and I can=E2=80=99t test that = where I am.<o:p></o:p></p><p> <o:p></o:p></p><p>- --Dave = <o:p></o:p></p><p> <o:p></o:p></p><p>Dave Edelman = <o:p></o:p></p><p> <o:p></o:p></p><p>From: Argus-info = <[email protected]> On = Behalf Of Monah Baki <br>Sent: Thursday, October 18, 2018 9:09 AM = <br>To: Eric Kinzie <[email protected]> <br>Cc: Argus = <[email protected]> <br>Subject: Re: [ARGUS] Akamai = WAF <o:p></o:p></p><p> <o:p></o:p></p><p>Hi Eric, = <o:p></o:p></p><p> <o:p></o:p></p><p>I bumped the = ARGUS_CAPTURE_DATA_LEN value to 2048, so running ratop -S localhost:561 = -s trans stime saddr:40 sport sco daddr dport dco suser duser:2048, I = can't see the rest of the duser column, gets chopped off, probably = displays 50 characters only (small monitor). Is there a way to overcome = this?<o:p></o:p></p><p> <o:p></o:p></p><p>Thanks = <o:p></o:p></p><p>Monah <o:p></o:p></p><p> <o:p></o:p></p><p>On = Thu, Oct 18, 2018 at 8:47 AM Eric Kinzie <[email protected] <<a = href=3D"mailto:[email protected]">mailto:[email protected]</a>> > = wrote: <o:p></o:p></p><p> On = October 17, 2018 12:47:43 PM EDT, Monah Baki <[email protected] = <<a = href=3D"mailto:[email protected]">mailto:[email protected]</a>> = > wrote: <br> >Hi all, = <br> > = <br> >We are using akamai = WAF services to protect our webserver. Currently = <br> >running the latest = argus/client on the webserver. When running ratop, = <br> >the = <br> >SrcAddr shows only = the akamai IP <br> = >(a23-212-3-119.deploy.static.akamaitechn*) = <br> >hitting our = webserver. <br> >Akamai = confirmed True-Client-IP is enabled and we should be able to see = <br> >the = <br> >real IP in the = request header. Can I get this info when using ratop? = <br> > = <br> > = <br> = >Trans = StartTime &nbs= p;  = ; SrcAddr = <br> >Sport = <br> = >sCo = DstAddr Dport = dCo &nbs= p;  = ; srcUdata <br> = > &nb= sp; &nbs= p;  = ; dstUdata = <br> > = 14 12:42:39.209029 = a23-212-3-119.deploy.static.akamaitechn*.49057 = <br> > = US www.ntis.gov.https <<a = href=3D"http://www.ntis.gov.https">http://www.ntis.gov.https</a>> = ; ZZ <br> = >s[50]=3D............s~V-...Tl....x..`...<.#.4^.+..a ..+... = <br> = >d[50]=3D....Y...U..[.f...=3D...|.I....:.t..?..:Yc...& O.-G]. = <br> > = 2 12:45:50.752456 = a23-212-53-84.deploy.static.akamaitechn*.61219 = <br> > = US www.ntis.gov.https <<a = href=3D"http://www.ntis.gov.https">http://www.ntis.gov.https</a>> = ; ZZ <br> = >s[50]=3D...........g.....E{.K.:S.4..4.e.F_..^.A."Rx o#Rr&3 = <br> = >d[50]=3D....Q...M..[.g>.....*..... ....G.as.V..y..d o#Rr&3 = <br> > = <br> > = <br> >Thanks = <br> >Monah = <br> = <br> Since this value is in = the http headers and, in this case, https is used you will not be able = to see the address in the Argus user buffers. For non-encrypted = http, set the ARGUS_CAPTURE_DATA_LEN to something large enough to get = all of the http headers and then the duser column in ratop should show = what you want.<o:p></o:p></p><p>-----BEGIN PGP SIGNATURE----- = <o:p></o:p></p><p>iF0EARECAB0WIQQP+UHquEepll566aqXCCyZOY1FIQUCW8yOQgAKCRC= XCCyZOY1F = <br>IfgdAJ9kn76NjN9FMc8PsYulqX7s3Z5pFQCffeFLqP2zaRxGzCaortLyHrq5CDY=3D = <br>=3DWPxX <br>-----END PGP SIGNATURE----- = <o:p></o:p></p></div></body></html> ------=_NextPart_000_0001_01D46929.8DF16490--