Forum Discussion
ASM attack signature staging for specific attack signature
Hi All, I would like to perform signature blocking setting (Alarm, Block) for specific attack signature (Signature ID).
How can i do it on BIG-IP version 11.5 ?
- Erik_NovakEmployee
Individual signatures cannot be assigned directly to security policies, nor can the learn, alarm, and block flags be set on an individual signature basis. "Signature sets" are entities which are assigned to specific security policies. Different signature sets may require a different level of blocking which apply only to them. When a signature set is assigned to a policy, the blocking action (learn/alarm/block) can be set differently for each assigned set.
while Erik is right you could work around this by creating your own signature set with just that signature in it. this will get annoying if you have many signatures you want this for, but if it is just a couple it might help you out.
- K_K_Thet_162361Nimbostratus
Thanks Erik and Boneyard,
If F5 can allow us to do signature staging setting for specific attack signatures in signature set, it is more flexible to configure attack signature.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com