Forum Discussion
ASM signature update enforcement
Hi guys,
We have ASM policies in blocking mode and realtime policy building disabled on them. Now my question is when there are new signature as a result of update, would them be enforced at any point of time? I understand they will be put in staging after signature update, but I am not sure if they are taken out of staging if we have the policy building disabled? Can you please advise?
Thanks in advanced
- nathe
Cirrocumulus
RasGhz, the new signatures (and optionally updated ones too if you check the box) will be in Staging until the Enforcement Readiness Period (default is 7 days) is over and there have been no violations on them. At this point you will need to remove them from staging by selecting Enforce. If there were any ones that did trigger a violation you need to double check whether it was a true positive - and Enforce - or a false positive - disable the signature.
So, to confirm, it is not an automatic process.
Hope this helps,
N
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com