Task 1: Onboard Application
Goal | Start protecting Juice Shop Application with FortiWeb Cloud |
Task | Onboard Application in FortiWeb GUI |
Verify task completion | Your Application will show up in the Application list. |
Add Application
Open the Applications view from top left menu bar, and then click, on + ADD APPLICATION
Tab 1: “WEBSITE”
- In Web Application Name enter your FortiWeb Cloud StudentID number which you used to login to FortiWeb Cloud (found at the top right corner of the FortiWeb Cloud Screen).
InfoFor example, if your FortiWeb Cloud User is CSEAccount669@fortinetcloud.onmicrosoft.com, your Student ID would be: 669
Tab 2: Network,
- unselect “HTTP” as we want to force users to interact with FortiWeb using only HTTPS.
- For IP Address or FQDN enter the JuiceShop Public IP (which is the Ubuntu VM Public IP from your Terraform Output)
- For Port enter “3000”
- Select HTTP for Server Protocol. This is Juice Shop and it is NOT secure
- Click on Test Origin Server You should see a green box pop up that says “Test successfully”
- Choose Next
Tab 3: CDN
No Changes. You will notice the Selected WAF Region shows the Platform “Google Cloud Platform” and the Region.
InfoFortiWeb Cloud automatically chooses the platform and region based on the IP Address of the application. There is no user intervention required.
Tab 4: “SETTING”
Tab 5: “CHANGE DNS”
We are presented with very important information regarding DNS settings which need to be changed in order to direct traffic to FortiWeb Cloud. In this lab, we will not be doing this, as sometimes it can take a while for the DNS settings to propagate.
WarningTake Note of the IPv4 addresses and CNAME for use in a later step. Before you close!
You should now see your Application listed in FortiWeb Cloud. Note that the DNS Status is set to Update Pending This is expected, and we will ignore it.