Forum Discussion
Beginner in F5 ASM
Hi All,
I hope you are doing well.
I am currently learning about F5 ASM to add one more technical skill to my skill set. I already have good experience with firewalls (Palo Alto and Check Point)
As F5 ASM is not deployed in our environment and we use a different vendor WAF (Imperva)
I wanted to know what the normal procedure is to onboard a web application on F5 in production.
Which policy template do you choose (Rapid deployment, comprehensive, fundamental)
Also, what is the best practice for policy building in learning mode?
How are signatures enforced? After 7 days learning period, do you enforce all staging signatures learned or do some manual checks as well?
3 Replies
- Jeff_Granieri
Employee
Hi ankda18
You have a variety of options with F5 WAF if you want to stay in the SaaS realm consider Distributed Cloud WAAP which can reside anywhere - Cloud | On-Prem | SaaS Backbone. For BIG-IP WAF there are a number of good documents to get started with that can help raise your security posture in a stepping stone manner. I'd highly recommend checking out these links below and then come back as you will find answers to some of your questions above.
WAF Security Policy Templates
Good | Elevated | High | Maximum --> Protections
Do you have app developers/owners that will help with WAF policy? Are you planning on deploying a positive or negative security model? These basic questions will help guide to what type of WAF security policy to start with. - mwolf
Altocumulus
ASM protects the traffic via a virtual server. You first have to configure a virtual server with SSL termination. The BIG-IP has to decrypt the traffic in order in inspect the traffic. After the virtual server is created. You bound the ASM policy to the virtual server via the security tab.
I would create a ASM policy via the rapid deployment template. Once the policy is created select the correct applications that are being protected. This helps to install the correct attack signatures.
Also make sure that you have learning enabled for the policy. The learning engine is a large aide for building the policy when you have no knowledge of the application you are protecting. I recommend keeping the learning enable with manual acceptance enabled all the time. I speeds up updating the policy when application developers forget to tell you about changes to the application.
You should also play with BOT protection.
WAF are very different than network firewalls. They require understanding of HTTP and other application protocols. An example of web content is java script / ecmascript. ASM will inspect java script content for attacks.
You may want to take a F5 ASM traning course. The nomenclature used for ASM is different than what is used in general networking.
Before doing anything my suggestion is to read and maybe pass the F5 AWAF/ASM training by F5 F5 | Education Services Portal | RockU
If your company doesn't want to pay for some reason you can still go through:
Guide introduction and contents | BIG-IP ASM operations guide
(26) F5 Advanced WAF (formerly ASM) Demo Series - YouTube
F5 | Education Services Portal | Getting Started with BIG-IP Advanced WAF
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com