Nov 06, 2018

ASM Staging for a newly assigned VIP

I have a long ago created ASM Policy in blocking mode, automatic policy building, and setup with a staging period of 7 days. I assigned a newly created VIP this ASM policy 4 days ago. Reviewing logs, I see that a disallowed URL is appearing in event viewer as illegal event and unblocked.


Question: Why is the illegal URL not blocked? Question: Does staging apply beyond attack signatures and parameters to other settings?


  • Hi,


    in Application Security > Allowed URLs List, did you see protocol: [HTTP/HTTPS] for URL * wildcard on list?