Forum Discussion
P_Casoria_18761
Nimbostratus
Feb 16, 2015ASM module - efficacy testing
Hello everyone,
I've deployed an F5 BIG-IP 2000s with LTM and ASM inside my architecture and I need to test the efficacy of Web Application Firewall (ASM module).
I've deployed "WebGoat" applica...
gsharri
Altostratus
Feb 16, 2015Check to see which entity (file types, urls, parameters) learning mode is in effect Application Security>Policy Building>Settings: Explicit Entities Learning.
If they are set to "Never, wildcard only" then all entity types are allowed by default due to the wildcards on the entities list. ASM will block a request only if it violates file type length limits set on the wildcard (to use file types example).
Check blocking settings as Hannes recommended.
Ensure relevant attack signatures are assigned to the security policy.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects