<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security How-To Guides on Webscale Product Documentation</title><link>https://docs.webscale.com/docs/how-tos/security/</link><description>Recent content in Security How-To Guides on Webscale Product Documentation</description><generator>Hugo</generator><language>en</language><atom:link href="https://docs.webscale.com/docs/how-tos/security/index.xml" rel="self" type="application/rss+xml"/><item><title>Password Guidance</title><link>https://docs.webscale.com/docs/how-tos/security/password-guidance/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.webscale.com/docs/how-tos/security/password-guidance/</guid><description>&lt;p&gt;The Webscale Control Panel requires that you change your password every 90 days. A password must be at least 8 characters, and must contain at least one digit, one uppercase character, and one lowercase character. Webscale recommends using generated passwords and storing them in a secure password manager to avoid easy-to-guess passwords. Ensure that you do not use your Control Panel password for any other services.&lt;/p&gt;
&lt;p&gt;Webscale recommends using &lt;a href="https://docs.webscale.com/docs/how-tos/security/mfa/"&gt;Multi-Factor Authentication&lt;/a&gt;
 to provide an additional layer of protection to your access.&lt;/p&gt;</description></item><item><title>Security Monitoring</title><link>https://docs.webscale.com/docs/how-tos/security/security-monitoring/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.webscale.com/docs/how-tos/security/security-monitoring/</guid><description>&lt;p&gt;Security Monitoring is an add-on feature that allows for continuous monitoring of cloud resources for malicious activity. Potential security concerns are published to the Webscale Event Log where they can be reviewed and monitored in the Event Log Viewer.&lt;/p&gt;
&lt;h2 id="configuring-security-monitoring"&gt;Configuring Security Monitoring&lt;/h2&gt;
&lt;p&gt;In order to configure security monitoring, your account must be granted access to the Security Monitoring plan. Please contact Webscale Support if you need this feature enabled for your account.&lt;/p&gt;</description></item><item><title>Editing the Blocklist</title><link>https://docs.webscale.com/docs/how-tos/security/blacklist/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.webscale.com/docs/how-tos/security/blacklist/</guid><description>&lt;p&gt;Add IP addresses to the blocklist to block known-bad IPs from accessing the backend of your application. It&amp;rsquo;s also possible to add User-Agents to the blocklist by defining a pattern to match. You should add known-good IP addresses to the allowlist to allow them to access your application. For more information on adding IP addresses to the allowlist, see &lt;a href="https://docs.webscale.com/docs/how-tos/security/whitelist/"&gt;Editing the Allowlist&lt;/a&gt;
.&lt;/p&gt;
&lt;div class="alert alert-primary" role="alert"&gt;&lt;div class="h4 alert-heading" role="heading"&gt;Note&lt;/div&gt;
&lt;p&gt;To follow these instructions, log into Webscale Control Panel and click the three vertical dots menu &lt;i class="fa fa-ellipsis-v" aria-hidden="true"&gt;&lt;/i&gt; of the application box.&lt;/p&gt;</description></item><item><title>Editing the Allowlist</title><link>https://docs.webscale.com/docs/how-tos/security/whitelist/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.webscale.com/docs/how-tos/security/whitelist/</guid><description>&lt;p&gt;Add your local IP address to the Allowlist to ensure you always have access to the backend of your application. You should also add some IP addresses to the Blocklist to prevent them from accessing your application. You can find those instructions on &lt;a href="https://docs.webscale.com/docs/how-tos/security/blacklist/"&gt;Editing the Blocklist&lt;/a&gt;
.&lt;/p&gt;
&lt;div class="alert alert-primary" role="alert"&gt;
&lt;p&gt;To follow these instructions, log into Webscale Control Panel and click the three vertical dots menu &lt;i class="fa fa-ellipsis-v" aria-hidden="true"&gt;&lt;/i&gt; of the application box.&lt;/p&gt;
&lt;p&gt;On the menu that appears, click &lt;strong&gt;Edit&lt;/strong&gt;.&lt;/p&gt;</description></item><item><title>How to Configure Multi-Factor Authentication</title><link>https://docs.webscale.com/docs/how-tos/security/mfa/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.webscale.com/docs/how-tos/security/mfa/</guid><description>&lt;p&gt;Multi-factor authentication (MFA) is a way to help increase security by requiring users to authenticate with a device in addition to the standard username and password combination. Some examples of multi-factor authentication include SMS codes and authentication applications such as &lt;em&gt;Google Authenticator&lt;/em&gt; or &lt;em&gt;Authy&lt;/em&gt;. Multi-factor authentication on Webscale uses authentication applications only.&lt;/p&gt;
&lt;h2 id="configure-multi-factor-authentication-mfa"&gt;Configure multi-factor authentication (MFA)&lt;/h2&gt;
&lt;!-- TODO: Add screencaps --&gt;
&lt;table&gt;
	&lt;thead&gt;
			&lt;tr&gt;
					&lt;th&gt;&lt;/th&gt;
					&lt;th&gt;&lt;/th&gt;
			&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
			&lt;tr&gt;
					&lt;td&gt;
&lt;div class="box" &gt;
 &lt;figure itemprop="associatedMedia" itemscope itemtype="http://schema.org/ImageObject"&gt;
 &lt;div class="img"&gt;
 &lt;img itemprop="thumbnail" src="https://docs.webscale.com/images/roles-users/mfa-qr-code.png" alt="MFA QR Code"/&gt;
 &lt;/div&gt;
 &lt;a href="https://docs.webscale.com/images/roles-users/mfa-qr-code.png" itemprop="contentUrl"&gt;&lt;/a&gt;
 &lt;/figure&gt;
&lt;/div&gt;
&lt;/td&gt;
					&lt;td&gt;1. To enable multi-factor authentication yourself while logged in, visit your &lt;a href="https://control.webscale.com/profile" target="_blank"&gt;User Profile&lt;i class="ps-1 fa fa-external-link"&gt;&lt;/i&gt;&lt;/a&gt;
 and click the &lt;strong&gt;Enable MFA&lt;/strong&gt; button.&lt;br /&gt;&lt;br /&gt; Otherwise, if the role a user belongs to requires multi-factor authentication, it must be configured when the user initially logs in to the control panel. When they login, the user sees a QR code. Use the authenticator application on the device to scan this QR code.&lt;br /&gt; &lt;br&gt;&lt;br&gt;&lt;i class="fa-solid fa-circle-info"&gt;&lt;/i&gt;
Some examples of authenticator applications are &lt;em&gt;Google Authenticator&lt;/em&gt;, &lt;em&gt;Authy&lt;/em&gt;, &lt;em&gt;OnePassword&lt;/em&gt;, etc. Please refer to the software installation instructions for your specific device.&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;
&lt;div class="box" &gt;
 &lt;figure itemprop="associatedMedia" itemscope itemtype="http://schema.org/ImageObject"&gt;
 &lt;div class="img"&gt;
 &lt;img itemprop="thumbnail" src="https://docs.webscale.com/images/roles-users/mfa-verify.png" alt="MFA Code Entry - Verification"/&gt;
 &lt;/div&gt;
 &lt;a href="https://docs.webscale.com/images/roles-users/mfa-verify.png" itemprop="contentUrl"&gt;&lt;/a&gt;
 &lt;/figure&gt;
&lt;/div&gt;
&lt;/td&gt;
					&lt;td&gt;2. Once the user scans the QR code, the authenticator application on the user&amp;rsquo;s device will generate a 6-digit code, called a One-Time Password (OTP).&lt;br /&gt; Enter the generated OTP into the text field on the control panel, and click the &lt;strong&gt;Verify&lt;/strong&gt; button.&lt;br&gt;&lt;br&gt;&lt;i class="fa-solid fa-circle-info"&gt;&lt;/i&gt;
To ensure the enrollment was done correctly, the user must confirm by entering their current password in the box that appears after entering the OTP.&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;
&lt;div class="box" &gt;
 &lt;figure itemprop="associatedMedia" itemscope itemtype="http://schema.org/ImageObject"&gt;
 &lt;div class="img"&gt;
 &lt;img itemprop="thumbnail" src="https://docs.webscale.com/images/roles-users/mfa-code-entry.png" alt="MFA Code Entry - Login"/&gt;
 &lt;/div&gt;
 &lt;a href="https://docs.webscale.com/images/roles-users/mfa-code-entry.png" itemprop="contentUrl"&gt;&lt;/a&gt;
 &lt;/figure&gt;
&lt;/div&gt;
&lt;/td&gt;
					&lt;td&gt;3. Multi-factor authentication for the user is now enabled.&lt;br /&gt; For future logins, the user must use the authenticator application on their device to generate an OTP after they&amp;rsquo;ve successfully authenticated with their password. Note that checking the box for &lt;strong&gt;Remember this browser&lt;/strong&gt; will set a cookie so the MFA code is not needed again if you login from the same browser. &lt;br&gt;&lt;br&gt;&lt;i class="fa-solid fa-circle-info"&gt;&lt;/i&gt;
Users follow a similar process, starting at the User Profile, to change or reset their multi-factor authentication application. The user must be able to login using their existing multi-factor authentication device to make changes. If the user changes devices or applications and cannot login, please &lt;a href="mailto:support@webscalenetworks.com"&gt;Contact Support&lt;/a&gt;
.&lt;/td&gt;
			&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="troubleshooting"&gt;Troubleshooting&lt;/h3&gt;
&lt;p&gt;If the MFA token being generated is not validating and allowing the user to login, it&amp;rsquo;s possible the time settings for the user&amp;rsquo;s mobile device and computer do not match. The specifics for resolving this issue differ depending on the mobile device OS and the computer OS in use. Here are some helpful resources:&lt;/p&gt;</description></item><item><title>How to Use Webscale Secure Access</title><link>https://docs.webscale.com/docs/how-tos/security/secure-access/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.webscale.com/docs/how-tos/security/secure-access/</guid><description>&lt;p&gt;&lt;a href="https://docs.webscale.com/docs/how-tos/general/user-roles/"&gt;&lt;strong&gt;User Roles&lt;/strong&gt;&lt;/a&gt;
 can be used as an action in an optional web control, called &lt;strong&gt;Webscale Secure Access&lt;/strong&gt;, to protect sections of your application from the general internet. This increases security by ensuring that only users who you&amp;rsquo;ve invited and assigned to a role can access these sections. As an example, you can require users to use Webscale&amp;rsquo;s login form before accessing your website&amp;rsquo;s login form, and can enforce &lt;a href="https://docs.webscale.com/docs/how-tos/security/mfa/"&gt;multi-factor authentication (MFA)&lt;/a&gt;
 for these users as well.&lt;/p&gt;</description></item><item><title>Enabling Bot IP Shield</title><link>https://docs.webscale.com/docs/how-tos/security/bot-shield/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.webscale.com/docs/how-tos/security/bot-shield/</guid><description>&lt;p&gt;Bot IP Shield is an add-on feature from Webscale that allows you to protect your application from known attack sources. Webscale has partnered with &lt;a href="https://www.brightcloud.com/" target="_blank"&gt;Webroot’s BrightCloud® IP Reputation Service&lt;i class="ps-1 fa fa-external-link"&gt;&lt;/i&gt;&lt;/a&gt;
 to maintain IP reputation data that is updated every 5 minutes to reflect the latest attack sources.&lt;/p&gt;
&lt;p&gt;After enabling this feature, configure shielding for the application that you want to protect. Then, create Web Controls to handle traffic from sources that you consider a threat. For example, you could configure the Web Control to deny requests from a request IP if it is a known threat.&lt;/p&gt;</description></item><item><title>How to Block Countries from Accessing Your Site</title><link>https://docs.webscale.com/docs/how-tos/security/block-countries/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.webscale.com/docs/how-tos/security/block-countries/</guid><description>&lt;p&gt;It&amp;rsquo;s possible to use a Web Control to block countries from accessing your application. This is done by using the &lt;code&gt;Country of origin is...&lt;/code&gt; condition for the Web Control.&lt;/p&gt;
&lt;div class="alert alert-primary" role="alert"&gt;
&lt;p&gt;To follow these instructions, log into Webscale Control Panel and click the three vertical dots menu &lt;i class="fa fa-ellipsis-v" aria-hidden="true"&gt;&lt;/i&gt; of the application box.&lt;/p&gt;
&lt;p&gt;On the menu that appears, click &lt;strong&gt;Edit&lt;/strong&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;h2 id="create-the-web-control"&gt;Create the Web Control&lt;/h2&gt;
&lt;p&gt;Click &lt;strong&gt;Web Controls&lt;/strong&gt; on the menu. Then, click the &lt;strong&gt;Add A Web Control&lt;/strong&gt; button to go to the &lt;strong&gt;Edit Web Control&lt;/strong&gt; panel.&lt;/p&gt;</description></item><item><title>Installing SSL Certificates</title><link>https://docs.webscale.com/docs/how-tos/security/install-ssl/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.webscale.com/docs/how-tos/security/install-ssl/</guid><description>&lt;p&gt;E-commerce sites require encrypted connections to remain PCI complaint and accept credit card data. Encryption ensures secure transmission of credit card details, which prevents bad actors from intercepting the information. To encrypt connections for your website, you must have an SSL (TLS) certificate installed for your site. (&amp;ldquo;SSL&amp;rdquo; and &amp;ldquo;TLS&amp;rdquo; are widely-used acronyms for &amp;ldquo;Secure Sockets Layer&amp;rdquo; and &amp;ldquo;Transport Layer Security.&amp;rdquo; SSL is now deprecated. TLS is the successor of SSL.)&lt;/p&gt;</description></item><item><title>Troubleshooting and Researching a Security Breach</title><link>https://docs.webscale.com/docs/how-tos/security/security-breach/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.webscale.com/docs/how-tos/security/security-breach/</guid><description>&lt;p&gt;One of the most stressful things that can happen to an ecommerce business is to discover that your site has been hacked or otherwise compromised. Webscale offers protection to known attacks right out of the box, but there are additional steps you can take to increase the security of your site and prevent future attacks. These are accomplished through the usage of Web Controls. There are also some common steps you can take to find out if the site has already been compromised.&lt;/p&gt;</description></item></channel></rss>