Forum Discussion
About scan ASM VIP
I get through the software (Web Application Firewall detected by Acunetix) to scan my F5 ASM VIP (TMOS 11.3.1 HF6). Results show that the WAF is F5 ASM. How do I set in F5 ASM, that can prevent Acunetix scanning is not ASM F5.
5 Replies
- LEON_LI_38034
Nimbostratus

- LEON_LI_38034
Nimbostratus
- LEON_LI_38034
Nimbostratus
scan overview image link https://devcentral.f5.com/Portals/0/Users/146/34/38034/acunetix%20waf%20scan.JPG
first of all what is your exact goal? do you want to be able to scan the actual webserver without WAF? or do you want to disguise that a WAF is in front of the webserver?
i don't believe you can surpress the ASM cookie or rename it, so it is going to be detected.
Hello
Asm can be identified by its blocking page response or specifoc asm cookies injected. But if acunetix do like qualys, there is no real ways to hide that you are using asm as they fingerprint the tcp stack used by bigip (fingerprinting, tcp response latency,...)
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com