Forum Discussion
Accepting an attack signature then reversing the action
Hi;
If a junior admin accepted a learnt attack signature, thinking it is a false positive, then the senior admin decides to "un-accept" it as he recognized that it is not a false positive. How can the "accepted" signatures be located to be "un-accepted". is there a list of accepted attack signatures.
Kindly Wasfi
Hi,
You can check the signature that have been accepted in the history of the security policy under "Policy >> History" and "Policy >> Audit".
Then, you can then restore a previous version of the security policy (history menu) or go to the specific section where the user has accepted a signature (URL, Parameter)
Hi,
You can check the signature that have been accepted in the history of the security policy under "Policy >> History" and "Policy >> Audit".
Then, you can then restore a previous version of the security policy (history menu) or go to the specific section where the user has accepted a signature (URL, Parameter)
- Wasfi_182818NimbostratusPerfect. Thank you Yann
- Yann_Desmarest_Nacreous
Hi,
You can check the signature that have been accepted in the history of the security policy under "Policy >> History" and "Policy >> Audit".
Then, you can then restore a previous version of the security policy (history menu) or go to the specific section where the user has accepted a signature (URL, Parameter)
- Wasfi_182818NimbostratusPerfect. Thank you Yann
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com