For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Albert_252822's avatar
Albert_252822
Icon for Nimbostratus rankNimbostratus
May 09, 2016

Automatic vs manual deployment

Hi all,

 

What are the differences between deploying a policy automatically and manually? I guess the main difference is the Policy builder stage in the automatic mode which allows delete false positives before enforcing the policy. On the other hand, in the manual deployment it's also possible to delete false positives using the transparent mode during a determined period of time.

 

My questions are: - Are there more differences between a manual and an automatic deployment? - Based on your experience, when would be recommendable to use manual or automatic deployment? - After enforcing an automatic deployment, are only protected the url's and parameters learnt during the Policy builder or are all the parameters protected such in the case of manual deployment?

 

Thanks in advance

 

4 Replies

  • Hello,

     

    The Policy Builder and the staging/learning process is not really the same.

     

    You can deploy a security policy manually with staging of signatures and urls, parameters, file types. This will allow you to fine tune you policy based on the application.

     

    With Policy Builder, the engine build and fine tune the whole security policy. At the end, you should not have so much fine tuning to do.

     

    • Albert_252822's avatar
      Albert_252822
      Icon for Nimbostratus rankNimbostratus
      Hi Yann, But what happens if some parameters or urls aren't accessed during the learning with Policy builder, will the Policy builder evaluate them and included them on that "automatic fine tunning"?
  • Hello,

     

    The Policy Builder and the staging/learning process is not really the same.

     

    You can deploy a security policy manually with staging of signatures and urls, parameters, file types. This will allow you to fine tune you policy based on the application.

     

    With Policy Builder, the engine build and fine tune the whole security policy. At the end, you should not have so much fine tuning to do.

     

    • Albert_252822's avatar
      Albert_252822
      Icon for Nimbostratus rankNimbostratus
      Hi Yann, But what happens if some parameters or urls aren't accessed during the learning with Policy builder, will the Policy builder evaluate them and included them on that "automatic fine tunning"?