Forum Discussion
Rajit_171155
Nimbostratus
Sep 22, 2014Best practices for attack signature update/maintenance on ASM
We are looking for suggestions regarding best practices for attack signature update/maintenance on ASM in an university environment. We would like to have inputs for the following questions
How...
Thomas_Gobet_91
Cirrostratus
Sep 24, 2014I think there isn't any step by step documentation to do that by policy.
What you have is updating process by platform.
The only thing which is different is you have to update manually your policy with only what you want to activate. One problem would be on modification during your QA tests.
If you want to modify your prod policy it will load changes from your attack signatures update.
- Rajit_171155Sep 25, 2014
Nimbostratus
I would appreciate if you could elaborate more on how to update the policy manually. We have two exactly similar policy one for QA environment and for Prod. Once I update the attach signature ( security>options>attack signature update) how can I push the updates to the policies? I am not able to find any options in the menu to apply the attack signature updates to individual policy. Running code 11.2 and 11.5.1 - natheSep 26, 2014
Cirrocumulus
you won't, all policies will be updated. once the staging period is over (enforcement readiness) you'll see that you can enforce those attack signatures on each policy. see the Overview - Application - Action Items screen - xunil321_122934Nov 27, 2014
Nimbostratus
Sorry for my ignorance! Let's say the 'Generic Detection Signature' set released 1st of Nov is assigned to my policy app_test. Once I update the Attack Signature on 1st of Dec does this mean that the former 'Generic Detection Signature' set will be overwritten by the new one automatically?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
