The page has been translated by Gen AI.

WAF Preparation

Configure firewall open settings

Client (User) - SECaaS (WAF) - Origin Server Each segment requires firewall opening. For the information required to open the firewall (Source, Type, Protocol, Destination), please inquire via the Support Center > Contact menu.

Reference
Samsung SDS network users do not need to submit a separate firewall opening request.
  1. Please open the firewall for the segment where the client (User) connects to the SECaaS (WAF).
    • The default supported web ports for SECaaS are as follows.
      • http : 80, 8080, 8880, 2052, 2082, 2086, 2095
      • https : 443, 2053, 2087, 2096, 8443
    • For websites that use ports other than the default supported web port, fill out the WAF service request form to proceed with the service request. We will provide the Destination IP via the email account in the service request form. If, after applying SECaaS, the port changes (added or removed) or the Origin changes, the IP may change. If you email the security monitoring center account (securitucenter@samsung.com) in advance, we will inform you of the updated IP through the responsible person.
      • If you do not use an IPv6 IP, you do not need to register it.
      • The service application form can be downloaded and attached from the All Services > Security > WAF menu by clicking the WAF Service Request button, then on the Service Request page.
      • For information related to service application, please refer to the How-to guides’ Create WAF.
        SourceTypeProtocolDestination: SECaaS
        ClientHTTP, HTTPSTCP
        • IPv4: 162.159.141.5 / 172.66.1.3
        • IPv6: 2606:4700:7::102 / 2a06:98c1:58::102
        Table. Example of IP forwarding form
  2. Proceed with opening the firewall for the segment that connects to the Origin Server from SECaaS (WAF).
    • The origin server is the device that receives traffic from SECaaS. (e.g., LB, server, etc.)
    • The firewall or security device in front of the origin server must allow a specific range.
      • Cloudflare IP range information: https://www.cloudflare.com/ko-kr/ips/
      • If you do not use an IPv6 IP, you do not need to register it.
        Caution
        We recommend blocking web traffic (HTTP, HTTPS) outside the specified range. If not blocked, the Origin IP may be exposed, leading to attacks that bypass SECaaS, and such bypass attacks are difficult to monitor; please note this.

Authenticate SECaaS domain

To verify the ownership of the registered domain, you need to create a host and add a TXT record for domain verification to DNS for authentication.

  • Authentication typically takes about 15 minutes after registration, but can take up to 24 hours depending on the environment. For example, when registering www.test.com, you must create and enter the Host and TXT Record values we provide into DNS.

Applying SECaaS Certificate

You can select and use either the certificate provided by SECaaS or the certificate provided by the customer. Certificate installation is possible only when HTTPS is prepared for the domain, and if the certificate is not installed, HTTPS communication will be unavailable.

1. When using SECaaS certificate

  • A new SSL certificate used between the Client ↔ SECaaS server will be generated.
  • Domain owner verification (validation) is required for the generated SSL certificate. The verification process is carried out by creating or entering the provided HOST and CNAME values in DNS.
  • Certificates cannot be extracted and delivered, and there is an automatic renewal feature, so no separate renewal is required.
  • Authentication typically takes about 15 minutes after registration, but may take up to 24 hours depending on the environment.

2. When using a client (Custom) certificate

  • Provide the Full chain certificate, Key File, and Key Value.
  • An API communication issue occurs when registering a single certificate. (Only pfx, pem, cer files are supported)
  • The renewed certificate must be provided for renewal before the certificate expires.
How-to guides
WAF Service Application