Forum Discussion
Best practice to put security signatures in blocking mode
What is the best practice to put security signatures in blocking mode. Should we put security signatures in blocking mode before putting it in production or will put it in detection mode and after analyzing the traffic we will put them in blocking mode one by one? If we will follow second method is there any possibilities to block legitimate traffic suddenly when we will change any signature in blocking mode. Do we have any best practice document on this.
4 Replies
im afraid there won't be any best practice because it just differs per requirements of the user.
do you want to be more safe and risk (some) false positives, put them into blocking right away.
do you want to be a little less safe put them info staging and see if they are hit, investigate and after staging enable them.
- Rchattop_307189
Nimbostratus
is it possible to put few of the known malicious signatures in blocking mode initially and rest of the signatures in detection mode.
- nag_54823
Cirrostratus
Yes. It's possible. We need to enable signature staging and enforce each signature individually which will go to blocking mode.
- Rchattop_307189
Nimbostratus
thanks a lot
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com