Forum Discussion
ASM IP Exceptions
- Jul 02, 2020
You need to leave Alarm enabled for malicious IP - in such case you will have ability to monitor how it works and detect (but not prevent) possible attack
Hello Crowe,
- Is your IP Intelligence database update periodically?
- In what IP Intelligence category do you have false-positives? Only in one or in several? If in one, then may be you can just disable this category.
- Learning works in any mode (Transparent or Blocking). You should see learning suggestions on "Security ›› Application Security : Policy Building : Traffic Learning" page.
Thanks, Ivan
- croweJun 30, 2020Cirrus
- Hello, the category that seems to be blocking the valid traffic is "Botnets", you would still recommend removing that category? or would I make adjustments on the policy learning section?
- Ivan_ChernenkiiJul 01, 2020Employee
Hello Crowe,
Image is not available...
If these are different IP addresses, but from the same subnet, then you can just add this subnet into Application Security : IP Addresses : IP Address Exceptions and Ignore IP Intelligence for it.
If these are totally different IP addresses, but all of them are valid - it sounds strange for me, but in this case you can disable the whole category, to not add them one by one as exception via learning.
If both case aren't good for you, then yes - proceed through the learning.
Thanks, Ivan
- croweJul 01, 2020Cirrus
It is strange indeed as it is always different public IP addresses being blocked, that is why we have ended up with three pages of /32 addresses in the IP exceptions list. Yesterday was the first day in two weeks since I have received a block, I'll give it more time to see if they are consistently the same category. Thank you.
The image was just the details of what I'm seeing in ASM logs regarding the latest block.
- croweJul 01, 2020Cirrus
Unfortuantely, the false positives are coming in under different categories. I just got a new one that is "Windows Exploits - Scanners".
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com