Forum Discussion
ASM ready to be enforced
Dears, The status ( ready to be enforced) appears after the (staging-tightening period) or after two times of it , ex if the period 7 days , the status ( ready to be enforced) will appear after 7 days or after 14 days
6 Replies
- Ido_Breger_3805Historic F5 Account
Ahalan Hamzeh, The status appears after the staging period is over (7 Days for signatures by default). Cheers, Ido
- Hamada_Tabosha_
Nimbostratus
thank you ido , another question please , I red in the ASM training manual the follwoing : (after 7 days no more learning suggestions are accumulated, but nothing else happens. staging ends when the entity has had no accumulated learning suggestions for period equal to the staging period)
now what i understand that : 7 days (staging with suggestions ) and from 7-13 days (staging with no suggestions ) then after 14 days ( no staging ) ..please correct me
- Ido_Breger_3805Historic F5 Account
Think about staging as a timer which was set to 7 days. Now, each time there is a policy change event on the staged entity, the timer is reset back to count down 7 days again. Example: you have a new parameter called username which you configured with a specific character set - only allow a-z and A-Z characters. After 2 days, you see a request with the O'reilly value in the username parameter and you have a suggestion to accept the ' metacharacter on the username parameter value. At this moment, the staging timer has 5 days left, however, if you accept the learning suggestion, it will reset itself to 7 Days and start to count down again. The reason behind this functionality is to give the ASM admin a period (staging period) in which if this time has passed , and no changes happened to the staged entity (it can a parameter, a file , a URL etc.) it means that this entity's configuration is accurate (it doesn't create false positives anymore)and it is ready to be enforced. Ya Salam.
- Hamada_Tabosha_
Nimbostratus
ido thank u , but what they mean by this sentence : (Staging ends when the entity has had no accumulated learning suggestions for the period equal to the staging period) ?????
- Ido_Breger_3805Historic F5 Account
They mean that that staging period ends (meaning that that the entity will be shown with a suggestion to be enforced) after the specified time has expired and during that time no learning suggestions have been accepted. So for example: if you have a staging period of 7 days, and 7 days have passed since you last accepted a learning suggestion on that entity, the entity will be "ready to be enforced". Reading your quote from the manual, I think that manual perhaps is miss-leading because it doesn't mention that the staging period is reset to count down again only after a learning suggestion has been accepted. You can have many learning suggestions on a staged entity but unless you accept one of them (and then reset the timer of the staging period to its original time) , the staging period will end after 7 days since it started.
- Hamada_Tabosha_
Nimbostratus
Thaaank you Ido
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com