Forum Discussion
ASM Policy Allow traversal detection evasion only for specific URL
Starting in v13, it is possible to make granular enabling/disabling of signature checks on a per-URL basis. In this case, if the URL in question is, say, /index.html, then you can create that as an Allowed URL and disable the signature check for Directory Traversal using the Overridden Attack Signature settings within this URL.
If you wish to achieve this via an iRule, it can be done using the ASM::signature command and that's only been introduced in v13: https://devcentral.f5.com/wiki/iRules.ASM__signature.ashx
If you are running a version prior to v13, you can use ASM::unblock command to unblock a request that's been blocked with 'Attack signature detected' violation. However, you can't unblock a request when it's been blocked specifically with a particular Signature ID.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
