Synchronizing WAF Blacklisted IP Addresses to Indicators (WAF synchronizes black IP addresses to intelligence)
Playbook Overview
The WAF synchronizes black IP addresses to intelligence playbook synchronizes blacklisted IP addresses in WAF to SecMaster Indicators module and automatically generates the corresponding indicators.
You need to manually enable this playbook. This playbook takes effect immediately after the configuration is complete and is executed every other day.
Prerequisites
- Your SecMaster professional edition is available.
- SecMaster has obtained the WAF ReadOnlyAccess permission for the read-only permission on WAF APIs. Perform the following steps to check whether SecMaster has obtained the WAF ReadOnlyAccess permission: If the permission is not allocated, allocate it to SecMaster by referring to Authorizing SecMaster.
- Log in to the SecMaster console as an administrator.
- Click
in the upper left corner of the page and choose Management & Governance > Identity and Access Management. - In the navigation pane on the left, choose Agencies. On the displayed page, click the SecMaster_Agency agency to go to the SecMaster_Agency agency page.
- Click the Permissions tab. If the permission list contains the WAF ReadOnlyAccess permission, SecMaster has obtained the WAF ReadOnlyAccess permission. It means SecMaster has the read-only permission for WAF APIs.
Figure 1 Viewing agency authorization records
Procedure
- Log in to the SecMaster console.
- In the navigation pane on the left, choose Workspaces > Management. In the workspace list, click the name of the target workspace.
Figure 2 Workspace management page
- In the navigation pane on the left, choose Security Orchestration > Playbooks.
Figure 3 Accessing the Playbooks tab
- On the Playbooks page, search for the WAF synchronizes black IP addresses to intelligence playbook and click Enable in the Operation column of the playbook.
- In the dialog box displayed, select the initial playbook version v1 and click OK. If the Playbook Status of the WAF synchronizes black IP addresses to intelligence playbook changes to Enabled, the playbook has been enabled successfully.
Implementation Effect
If the playbook takes effect, go to the page of the target SecMaster workspace. On the Indicators page, you can view the new indicators.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot