Forum Discussion

K_K_Thet_162361's avatar
K_K_Thet_162361
Icon for Nimbostratus rankNimbostratus
Feb 25, 2015

ASM attack signature staging for specific attack signature

Hi All, I would like to perform signature blocking setting (Alarm, Block) for specific attack signature (Signature ID).

 

How can i do it on BIG-IP version 11.5 ?

 

 

  • Individual signatures cannot be assigned directly to security policies, nor can the learn, alarm, and block flags be set on an individual signature basis. "Signature sets" are entities which are assigned to specific security policies. Different signature sets may require a different level of blocking which apply only to them. When a signature set is assigned to a policy, the blocking action (learn/alarm/block) can be set differently for each assigned set.

     

  • while Erik is right you could work around this by creating your own signature set with just that signature in it. this will get annoying if you have many signatures you want this for, but if it is just a couple it might help you out.

     

  • Thanks Erik and Boneyard,

     

    If F5 can allow us to do signature staging setting for specific attack signatures in signature set, it is more flexible to configure attack signature.