Forum Discussion

ankda18's avatar
ankda18
Icon for Nimbostratus rankNimbostratus
Aug 13, 2026

Beginner in F5 ASM

Hi All,

I hope you are doing well.

 

I am currently learning about F5 ASM to add one more technical skill to my skill set. I already have good experience with firewalls (Palo Alto and Check Point)
As F5 ASM is not deployed in our environment and we use a different vendor WAF (Imperva)
I wanted to know what the normal procedure is to onboard a web application on F5 in production.

Which policy template do you choose (Rapid deployment, comprehensive, fundamental)

Also, what is the best practice for policy building in learning mode?

How are signatures enforced? After 7 days learning period, do you enforce all staging signatures learned or do some manual checks as well?

3 Replies

  • Hi ankda18​ 

    You have a variety of options with F5 WAF if you want to stay in the SaaS realm consider Distributed Cloud WAAP which can reside anywhere - Cloud | On-Prem | SaaS Backbone.  For BIG-IP WAF there are a number of good documents to get started with that can help raise your security posture in a stepping stone manner.  I'd highly recommend checking out these links below and then come back as you will find answers to some of your questions above.

    WAF Security Policy Templates
    Good | Elevated | High | Maximum --> Protections

    Do you have app developers/owners that will help with WAF policy?  Are you planning on deploying a positive or negative security model?  These basic questions will help guide to what type of WAF security policy to start with.  

  • ASM protects the traffic via a virtual server. You first have to configure a virtual server with SSL termination. The BIG-IP has to decrypt the traffic in order in inspect the traffic. After the virtual server is created. You bound the ASM policy to the virtual server via the security tab.

    I would create a ASM policy via the rapid deployment template.  Once the policy is created select the correct applications that are being protected.  This helps to install the correct attack signatures. 

    Also make sure that you have learning enabled for the policy.  The learning engine is a large aide for building the policy when you have no knowledge of the application you are protecting. I recommend keeping the learning enable with manual acceptance enabled all the time. I speeds up updating the policy when application developers forget to tell you about changes to the application.

    You should also play with BOT protection.

    WAF are very different than network firewalls. They require understanding of HTTP and other application protocols. An example of web content is java script / ecmascript. ASM will inspect java script content for attacks.  

    You may want to take a F5 ASM traning course. The nomenclature used for ASM is different than what is used in general networking.