Security Hardening
security enhanced (selinux, csrf for enduser, csp, key management) support this feature constraints access to the ics linux system (ics linux applications) with the minimal set of resources they need in the serial console, enter 13 to select security operations ( selinux, csp, csrf for enduser, key management, waf ) choose the selinux mode this feature is enabled by default with system running in enforcing mode to change the mode enter 1 and choose the following options permissive does not deny any operations but only logs access vector cache (avc) messages enforcing denies operations based on selinux policy rules and logs access vector cache (avc) messages selinux cannot be disabled csrf in enduser portal csrf (cross site request forgery) is a type of web security vulnerability that can be exploited to make a victim's browser perform unwanted actions on ics webserver these attacks are mitigated by using csrf tokens, which help verify that requests originate from the user's intended actions enter 2 to enable/disable csrf in enduser portal disable csrf in enduser portal enter 0 to disable csrf enable csrf in enduser portal enter 1 to enable and to protect the enduser portal from csrf attack content security policy content security policy (csp) is an added layer of security that helps to detect and mitigate certain types of attacks, including cross site scripting (xss) and data injection attacks these attacks are used for everything from data theft, to site defacement, to malware distribution it is strictly recommended to remove any existing csp header prior to upgrade, from ui system > configuration > security > advanced configuration enter 3 to enable/disable content security policy (csp) csp is enabled by default beginning from release 22 7r2 onwards disable csp enter 0 to disable csp enable csp enter 1 to enable csp csp header sample content security policy script src 'nonce xxxxxxxxxxxxxxxx' 'strict dynamic'; object src 'none'; base uri 'none'; rotate internal storage key is supported beginning from release 22 8r2/ 25 x onwards enter 4 to rotate the internal storage key this process encrypts "secure” elements like passwords when storing them internally and ensures the encryption key is unique and random for every ics instance enter y to start the internal storage key rotation and after completion services will restart selinux security policy the ics system provides an enforcing only selinux capability, ensuring that even the root user or admin cannot switch selinux to permissive mode without rebooting the system rebooting is considered a significant event and should not occur without being noticed or logged by the ics administrator the primary goal of this feature is to ensure that selinux functions as the exclusive security policy enforcement mechanism for the ics system selinux must operate strictly in enforcing mode, making it tamper proof and preventing unauthorized actions from bypassing or disabling its enforcement selinux mode will still be enforced mode only, even if the administrator selects to disable selinux security policy however, disabling selinux security policy is not a recommended action unless explicitly requested by ivanti support it is recommended to change the selinux security policy to enabled status as soon as the support activity is completed upon system boot, a menu is presented to the user with a prompt to determine the selinux security policy the user has 15 seconds to decide whether to switch to disable selinux security policy or remain in enable selinux security policy to enable selinix security policy, perform the following in the serial console, enter 13 to select security operations ( selinux, csp, csrf for enduser, key management, waf ) enter 5 to enable the selinux security policy select n (default) to enables the selinux security policy or timeout without choosing any option also enables the selinux security policy or select y to disables the selinux security policy to enable selinux mode to permissive or enforcing follow the steps in the serial console, enter 13 to select security operations ( selinux, csp, csrf for enduser, key management, waf ) choose the selinux mode this feature is enabled by default with system running in enforcing mode to change the mode enter 1 and choose the following options enter 1 to enable permissive mode (only after rebooting with disable selinux security policy system can go to permissive mode) enter 2 to enable enforcing mode to make selinux policy tamper proof and preventing unauthorized actions from bypassing or disabling its enforcement if you have disabled the selinux security policy to re enable the selinux security policy enter 5 to enable the selinux security policy security enhanced waf operation configuring web application firewall in ui web application firewall (waf) protects web applications by filtering and monitoring http traffic, preventing attacks such as sql injection, cross site scripting (xss), and other web exploits ics waf inspects web traffic terminating on all the gateway network interfaces waf filtering and monitoring is supported beginning from release 22 8r2/25 1 0 0 to configure waf on ics select system > configuration > security > web application firewall select the required mode if detection mode selected, then it monitors and logs potential threats without blocking them if protection mode selected, then it actively blocks and mitigates detected threats browse to choose the waf rule set package file and click upload & activate if any new waf rules packages are released, they will be made available on software download https //portal ivanti com/customer/product downloads page waf rule set package is a set of generic attack detection rules designed to work with waf engine browse and upload the new waf rule set package to change the active waf rule set version current active waf rule set package 1 0 3 click reset to restore waf rule set package to its default version click rollback to revert the waf rule set package to previous version enter the rule id and click add to exclude it from the list rule id can be retrieved using log message a log message is illustrated in detail log message parameters descriptions 2024 12 17 00 54 01 ive \[127 0 0 1] root admin(admin users)\[ ]\[] waf message message header msg xss attack detected via libinjection warning message id 941100 unique rule id data matched data xss data found within args\ txtnewruleid \<script> data comparision severity 2 log severity hostname ip address uri /dana admin/security/wafconfig cgi uri link the waf rule set is a set of pre configured rules designed to detect and prevent various web based attacks each rule is assigned with an unique identifier known as a rule id (eg 942100) configuring web application firewall in console enabling web application firewall might have some impact on the performance of the ics appliance this feature constraints access to the ics linux system (ics linux applications) with the minimal set of resources they need in the serial console, enter choice 13 to select security operations (selinux, csp, csrf for enduser, key management, waf) and then choice 6 to enter waf security operations sub menu enter 1 to select the required mode by default waf is in protection mode , enter 0 to change to mode to detection mode it is recommended to move from waf protection to detection in case traffic gets blocked detection mode monitors and logs potential threats without blocking them protection mode actively blocks and mitigates detected threats selinux verbose log administrators can toggle selinux verbose logging to control the detail level of selinux related logs this feature is only available when selinux is operating in permissive mode it does not work in enforcing mode verbose logging provides detailed information on access denials, selinux actions, and suppressed log entries, helping administrators debug selinux policy configurations however, verbose logging reverts to its default disabled state after a system reboot, requiring manual re enablement in the serial console, enter choice 13 to select security operations (selinux, csp, csrf for enduser, key management, waf) and then choice 7 to enter enable/disable selinux verbose log sub menu enter 1 to enable selinux verbose logging this allows suppressed/denied access logs to appear for debugging purposes enter 0 to disable selinux verbose logging this turns off the verbose logging and reduce the verbose entries in logs these settings apply at runtime only; they do not persist after a system reboot verbose logging is restricted to permissive mode; it does not work in enforcing mode permission is denied when enforcing mode is enabled host header validation ics will enable the host header validation to ensure protection by default, if user has not enabled it earlier on disabling this option via admin console will disable the validation setting on all the ics interfaces this completely disables the validation of end user access or admin access against host header and unlock the respective page access in the serial console, enter choice 13 to select security operations (selinux, csp, csrf for enduser, key management, waf) and then choice 8 to enter enable/disable host header validation sub menu enter 0 to disable host header validation disables the validation setting on all the ics interfaces enter 1 to enable host header validation to protect and validate the interfaces next generation web server web server is used for reverse proxy, load balancing, and caching it provides https server capabilities and is mainly designed for maximum performance and stability reduces the waiting time to load a website speeds up performance by routing traffic to web servers acts as an inexpensive and robust load balancer offers scalability and the ability to handle concurrent requests next generation web server is enabled by default and cannot be disabled from 25 1 0 0 release onwards with next generation web server enabled, pushconfig from older releases to 22 8r2 and 25 x is not supported radius configuration this features change the queue mechanism of radius auth server request from lifo to fifo in the serial console, enter 15 to select radius configurations enter 1 to change the radius auth request queue mechanism from lifo to fifo to restore back to lifo enter 2 audit logs a snapshot of the system state captures details that can help support center diagnose system performance problems the system stores up to ten snapshots, which are packaged into an encrypted "dump" file that you can download and then e mail to global support center to enable audit logs select maintenance > troubleshooting > system snapshot to display the configuration page click the checkbox include audit log under system snapshot options enable selinux audit logs selinux audit logs can be very useful for finding out security attacks via selinux denials and also for debugging purpose sample selinux denial message type=avc msg=audit(1223024155 684 49) avc denied { getattr } for pid=2000 comm="httpd" path="/var/www/html/file1" dev=dm 0 ino=399185 scontext=unconfined u\ system r\ httpd t\ s0 tcontext=system u\ object r\ samba share t\ s0 tclass=file tls 1 3 support to enable tls 1 3 select the checkbox enable tls 1 3 , under inbound settings allowed ssl and tls version tls for certauth would be tls 1 2 even if tls 1 3 is selected by admin note that connection between server and client still would be tls 1 3 tls 1 2 is only used for inner tls (to send as payload in tls 1 3 packets) while enforcing tls 1 3 the following confirm cipher change message is displayed client certificate authentication may not work on all browsers with tls 1 3 enabled for more details, refer to these articles impact on client launchers https //forums ivanti com/s/article/enabling tls 1 3 versions for inbound ssl connections cause older version pulse isac client failure to establish connection and impact on browser based cert auth https //forums ivanti com/s/article/impact on browser based certificate authentication with tls 1 3 enforcement on selecting accept only tls 1 3 option, only tls1 3 version and its related ciphers are enabled while other versions and their related cipher suites are rejected
