Forum Discussion
AFM Learn-Only Signatures Dropping Traffic
I was under the impression initially that if you had these dynamic signatures set to learn-only you weren't going to drop traffic. I have set all of these vectors to enforced and it looks like the event logs show drops so is this in fact enforcing/dropping?
- nathe
Cirrocumulus
ipman,
What you are seeing in the logs is right, the Attack Vectors are enforced so AFM is dropping traffic. The Learn Only mode you are seeing is referencing Dynamic Signatures. Here, the AFM is doing Behavioural analysis and creating Dynamic Signatures on the fly, if required. Looking at your logs it's not triggering a Dynamic Signature, rather the default BADACK attack vector.
See
Hope this helps,
N
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com