Forum Discussion
Asm doubt
What is the best practice ?
Adding all parameters for application and removing the wildcard parameter from staging and keeping all in enforcement mode ?
Or to keep a hybrid model, adding required parameter and putting them in enforcement mode and keep wildcard parameter in staging ?
- samstepCirrocumulus
It depends on your application and its size. Generally speaking you want a tight policy which will ensure maximum protection against attacks. If staging is enabled many attacks will not be blocked! If your application is small-medium then yes, you should whitelist all parameters an enforce everything. This is provided your application never or rarely changes (e.g. OWA, Oracle appls etc). If you are protecting an "agile" application which changes weekly and maybe even daily then hybrid approach is needed
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com