Manual Chapter :
Publishing Security Policies and Profiles to Application Templates
Applies To:
Show VersionsBIG-IQ Centralized Management
- 6.0.1
Publishing Security Policies and Profiles to Application Templates
About making security policies and profiles available to
application templates
You can add security policies and profiles to your applications to make them
more secure. You assign these policies and profiles to an application using an
application template. The BIG-IQ® Centralized
Management system provides a set of default security policies and profiles to make it
easier to add security to your applications. You can use these default policies and
profiles, modify them, or for Web Application Security policies, create your own
defaults. You can make these types of security policies or profiles available to an
application template:
- Network Security firewall policies
- Web Application Security policies
- Shared Security DoS profiles
- Shared Security logging profiles
This is the general process for publishing security policies or
profiles so that they can be used in an application template and application.
- The security administrator uses the Configuration screens of BIG-IQ® Centralized Management to edit a policy or profile so that it can be marked as available to application templates, and make any other needed changes. You can use the default profiles or policies provided, or identify other application security policies and logging profiles as defaults for the application templates. The security administrator can then publish policies and profiles one at a time, or publish several at a time if there are no other changes to make.You may have different administrators responsible for configuring different security areas, such as firewall security or web application security. If so, multiple administrators may need to be involved.
- The BIG-IQ administrator uses the Application screens of the BIG-IQ system to create an application template that includes the new security policy or profile.
- The application manager creates an application that uses the security policy or profile from the application template that contained it.
- The application manager saves the completed application, which causes the BIG-IQ system to automatically deploy the security policy or profile to the specified BIG-IP devices.
- Once the security policies or profiles are deployed, the application manager can use the associated application to monitor and manage those security policies or profiles on the BIG-IP devices.
If application changes are needed, the application manager or BIG-IQ
administrator makes them using the BIG-IQ Application screens. If policy or profile changes are needed, the appropriate security
administrator makes them using the BIG-IQ Configuration screens, and then deploys the
updated policy or profile. Once deployed, the updated policy or profile is automatically
available to the applications that use it.
Make a Network Security firewall policy available to an
application template
If you want to add a Network Security
firewall policy to an application, you must first make that firewall policy available in
an application template.
- Click.
- Review the application templates that are currently using firewall policies.
- Review what policies are already available to application templates by looking at the Available in Application Templates column.
- To view any application templates that use this policy, select the check box to the left of the policy name. This displays additional details about the policy in the area below the policy list. Then in the Related Items area, clickShow.
You use this information to verify that the expected policies have been made available to the application templates. This lets you consider the potential impact of changing or deleting a policy that is being used by an application template. - Publish the policy.
- To publish one or more policies at once, select the check box to the left of the policy names, clickMore, and selectMake available for templates.
- To publish a single policy while modifying that policy, click the name of the policy to modify and then on the left clickProperties. Then in theApplication Templatessetting, clickMake available in Application Templates.
- Save your work.
You can now select the
Network Security policy or policies from the application templates when creating an
application. The application manager can now create an application that uses the
security policy from the application template that included it. When the application is
created, the security policy is deployed as part of a partial deployment to the
specified BIG-IP devices.
If a security policy changes, applications using the security policy will
receive those changes when the updated policy is deployed to the BIG-IP
devices.
Make a Web Application Security application policy available to an
application template
If you want to add a Web Application Security
policy to an application, you must first make that policy available in an application
template.
You cannot make parent policies available in
application templates.
- Click.
- Review the application templates that are currently using application policies.
- Review what policies are already available to application templates by looking at the Available for Templates column.
- To view any application templates that use this policy, select the check box to the left of the policy name. This displays additional details about the policy in the area below the policy list. Then in the Related Items area, clickShow.
You use this information to verify that the expected policies have been made available to the application templates. This lets you review the potential impact of changing or deleting a policy that is being used by an application template. - Publish the policy.
- To publish one or more policies at once, select the check box to the left of the policy names, clickMore, and selectMake available for templates.
- To publish a single policy while modifying it, click the name of the policy to modify and then on the left clickGeneral Properties. Then in theApplication Templatessetting, clickMake available in Application Templates.
- Optionally, set a policy as the default for application templates. Select the check box to the left of the policy and clickMore, and selectUse as Default Policy.The BIG-IQ system supplies a default policy for application templates that you can modify, if needed. The policyis namedtemplates-default.
- Save your work.
You can now select the Web Application Security
policy from the application templates when creating an application. The application
manager can now create an application that uses the security policy from the application
template that included it. When the application is created, the security policy is
deployed as part of a partial deployment to the specified BIG-IP devices.
If a security policy changes, applications using the security
policy will receive those changes when the updated policy is deployed.
Make a logging profile available to an application
template
You make a logging profile available to an
application template so that it can then be used by an application. A logging profile is
used by security policies to select where events are logged, and which items (such as
which parts of requests, or which type of errors) are logged.
- Click.
- Review the application templates that are currently using the logging profile.
- Review what profiles are already available to application templates by looking at the Available in Application Templates column.
- To view any application templates that use this profile, select the check box to the left of the profile name. This displays additional details about the profile in the area below the profile list. Then in the Related Items area, clickShow.
You use this information to verify that the expected profiles have been made available to the application templates. This lets you know the potential impact of changing or deleting a profile that is being used by an application template. - Publish the profile.
- To publish one or more profiles, select the check box to the left of the profile names, and selectMake available for templates.
- To publish a single profile while modifying it, click the name of the profile to modify and then on the left clickProperties. Then in theApplication Templatessetting, selectMake available in Application Templates.
The default logging profiletemplates-defaultis shipped as part of the BIG-IQ system. - Save your work.
You can now select the
profile from the application templates when creating an application. The application
manager can now create an application that uses the profile from the application
template that included it. When the application is created, the profile is deployed as
part of a partial deployment to the specified BIG-IP devices.
If a
profile changes, applications using the profile will receive those changes when the
updated profile is deployed.
Make a DoS profile available to an application template
You make a DoS profile available to an
application template so that it can then be used by an application. DoS profiles define
how to protect against DoS attacks and can be used with a security policy.
- Click.
- Review the application templates that are currently using the DoS profile.
- Review what profiles are already available to application templates by looking at the Available in Application Templates column.
- To view any application templates that use this profile, select the check box to the left of the profile name. This displays additional details about the profile in the area below the profile list. Then in the Related Items area, clickShow.
You use this information to verify that the expected profiles have been made available to the application templates. This lets you know the potential impact of changing or deleting a profile that is being used by an application template. - Publish the profile.
- To publish one or more profiles, select the check box to the left of the profile names, and selectMake available for templates.
- To publish a single profile while modifying it, click the name of the profile to modify and then on the left clickProperties. Then in theApplication Templatessetting, selectMake available in Application Templates.
- Save your work.
You can now select the
profile from the application templates when creating an application. The application
manager can now create an application that uses the profile from the application
template that included it. When the application is created, the profile is deployed as
part of a partial deployment to the specified BIG-IP devices.
If a
profile changes, applications using the profile will receive those changes when the
updated profile is deployed.