Forum Discussion
Beginner in F5 ASM
Hi All,
I hope you are doing well.
I am currently learning about F5 ASM to add one more technical skill to my skill set. I already have good experience with firewalls (Palo Alto and Check Point)
As F5 ASM is not deployed in our environment and we use a different vendor WAF (Imperva)
I wanted to know what the normal procedure is to onboard a web application on F5 in production.
Which policy template do you choose (Rapid deployment, comprehensive, fundamental)
Also, what is the best practice for policy building in learning mode?
How are signatures enforced? After 7 days learning period, do you enforce all staging signatures learned or do some manual checks as well?
1 Reply
- Jeff_Granieri
Employee
Hi ankda18
You have a variety of options with F5 WAF if you want to stay in the SaaS realm consider Distributed Cloud WAAP which can reside anywhere - Cloud | On-Prem | SaaS Backbone. For BIG-IP WAF there are a number of good documents to get started with that can help raise your security posture in a stepping stone manner. I'd highly recommend checking out these links below and then come back as you will find answers to some of your questions above.
WAF Security Policy Templates
Good | Elevated | High | Maximum --> Protections
Do you have app developers/owners that will help with WAF policy? Are you planning on deploying a positive or negative security model? These basic questions will help guide to what type of WAF security policy to start with.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com