Forum Discussion

Check1t_282465's avatar
Check1t_282465
Icon for Nimbostratus rankNimbostratus
Apr 19, 2018

ASM Policy Differencial Enabled vs. Staging difference for Policy Signatures

Policy A shows a number of Policy Signatures 'Disabled'. Policy B shows Policy Signatures 'Enabled'. Could someone please confirm that if I go with the Enabled policy, that VIP with said policy will now have those signatures enforced per policy (e.g. if policy is in blocking mode, requests against enabled signature will be blocked).

 

Thank you!

 

  • The enabled signatures in policy B will be applied to the traffic but blocking requests which match signatures depends on several things:

     

    1. Policy enforcement mode must be set to Blocking

     

    2. Signatures must be enforced (staging disabled on each signature)

     

    3. Attack signatures must have Block checkbox enabled on the Traffic Learning screen

     

    Scott

     

  • Sidebar question to my original query regarding Policy A (Policy Signatures Disabled) vs. Policy B (Policy Signatures Enabled). If I take a specific attack signature, and I navigate via Security ›› Application Security : Attack Signatures. Lookup specific signature for Policy A, and it details ID, Learning, Staging (No), Learn, Alarm, Block, Enabled status. All good. However, when I attempt to lookup signature B, No entries found. If the Policy does not have the Signature, how can it be Enabled???

     

    Thanks again.