Page 1 of 1

TWAF tweaking

Posted: Tue Jun 23, 2015 3:03 am
by imadsani
I just setup TWAF along side Varnish on port 80 for a server, when I tested it myself things went fine but everything went haywire as soon as I redirected traffic to it. The pages took forever to load, when they loaded other times just an endless wait. So I removed TWAF from port 80 and everything got better.

My question, which file do I play with for TWAF's apache instance to get it to handle this traffic?

Re: TWAF tweaking

Posted: Tue Jun 23, 2015 9:08 am
by mikeshinn
What port did you config the TWAF to listen on?

Re: TWAF tweaking

Posted: Wed Jun 24, 2015 1:15 am
by imadsani
Initially I had it set up on port 80

Re: TWAF tweaking

Posted: Wed Jun 24, 2015 10:57 am
by mikeshinn
Was it also configured on port 80 when you setup a proxy in front of it?

Re: TWAF tweaking

Posted: Thu Jun 25, 2015 1:36 am
by imadsani
I don't follow.

The original setup had Nginx / PHP-FPM on port 8888 and Varnish & TWAF on port 80

Re: TWAF tweaking

Posted: Fri Jun 26, 2015 5:30 pm
by mikeshinn
Sorry if I wasnt clear, was the TWAF configured to intercept connections to port 80, and something else was configured to also listen on port 80?

Re: TWAF tweaking

Posted: Wed Jul 01, 2015 4:11 pm
by imadsani
Apologies for the late reply.

TWAF and Varnish were running side by side on port 80.

Edit: Would changing settings in the tortixd.conf file at /var/asl/etc/httpd/conf help?

Re: TWAF tweaking

Posted: Wed Jul 01, 2015 9:16 pm
by scott
Sure, all the rules of a standard /etc/httpd/conf/httpd.conf apply there.