Forum Discussion
ASM inline scanning
does anyone know if it is possible to use ASM with a general policy to scan traffic to many http servers without having to define all these as a virtual server?
with 11.4 i don't see the option to attach a policy to anything (IP forward, performance L4) except a standard virtual server.
- Thomas_GobetNimbostratus
To use ASM you have to define a standard virtual server with a http profile.
hmmm, but that would mean connecting directly to the backend IP right? means you do loose some normal configuration.
- Thomas_GobetNimbostratus
No you can define a wilcard virtual server on the external side (VLAN).
- Matt_DierickEmployee
Hi Boneyard,
You can follow Thomas recommendations but be careful regarding your ASM policy size. If you have many applications on the same policy, you will increase CPU load.
Take care. Matt
thanks, yeah that sounds logical. still doesnt feel like the way forward.
I would seriously guard against doing this. What are you trying to achieve? ASM policy should be customized per application -- the more broader and 'generic' you get - the less valuable the tool becomes, and after a while it starts looking like your corporate firewall, and about as useful.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com