Forum Discussion
ASM disable violations alarm just for specific requests
- Apr 17, 2017
RFC compliance is violation. Nearly every violation has learn/alarm/block settings for the policy. Their is no granularity beyond that. While you can unblock via an iRule their is no command available to disable the alarm only. Your only option is to have a separate policy that has alarm turned off for the violation. Copy your existing security policy. Modify it so the alarm flag is disabled for the RFC violation. Now go to local traffic policy for your virtual server and add a new rule above the existing asm policy rule. When the URI matches have it select the new policy. Make sure policy matching strategy is set to first match.
RFC compliance is violation. Nearly every violation has learn/alarm/block settings for the policy. Their is no granularity beyond that. While you can unblock via an iRule their is no command available to disable the alarm only. Your only option is to have a separate policy that has alarm turned off for the violation. Copy your existing security policy. Modify it so the alarm flag is disabled for the RFC violation. Now go to local traffic policy for your virtual server and add a new rule above the existing asm policy rule. When the URI matches have it select the new policy. Make sure policy matching strategy is set to first match.
Thanks for your answer, i think you have made it clear for me.
Regards, Muhannad
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com