For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

rezgui_180607's avatar
rezgui_180607
Icon for Nimbostratus rankNimbostratus
Mar 17, 2016

about the blocking mod

Dear all,

 

the period of enforcement readline will finish tomorow i would like to know what is the steps to apply the blocking mode?

 

the situation is: accepting many ligitim url and parameter in the learn period , the staging still activate ans i have many url,parameter and file type has "Not Enforced" in Enforcement Readiness for the policy builder.

 

Best Regards

 

2 Replies

  • Tzoori_Tamam_95's avatar
    Tzoori_Tamam_95
    Historic F5 Account

    When the "Staging" period is over it means that you will start seeing entities as "Ready to be enforced" in the Enforcement Readiness page. Tuning a policy manually is a process that requires some knowledge and it would be best if you go over ASM's Operations Guide in order to make sure you are following the right procedure for your security requirements.

     

  • If you enforce your entities (URLs, Parameters, File Types, etc..) 2 action will be performed:

    Remove all entities (explicit and wildcard) from staging for the selected entity type.
    Delete wildcard entities configured to learn all explicit entities.
    

    You can start enforcing what your are sure of URLs, Parameters, File types, etc.., and you keep the policy building running, to learn more, and do not forget to re add the Wildcard with learning enabled again to keep on learning.

    Regards