Forum Discussion
Rajit_171155
Nimbostratus
Sep 22, 2014Best practices for attack signature update/maintenance on ASM
We are looking for suggestions regarding best practices for attack signature update/maintenance on ASM in an university environment. We would like to have inputs for the following questions
How...
Thomas_Gobet_91
Cirrostratus
Sep 22, 2014Hi,
-
Attacks signatures should be updated as often as you can. You won't need to apply each version, it will depend on what you have to protect.
-
Again it depends on which security management you apply. To avoid some false positives, you have to change blocking signatures to staging mode. I usually do that, you'll avoid to be waked up at 3am for "nothing".
-
Yes you can do that. Each ASM policy is isolated from others. So on your QA policy, you can update a policy whereas on your prod one you don't apply the update.
nathe
Cirrocumulus
Sep 24, 2014I agree with Denny on that. Once you apply signatures, after the enforcement period is over you'll get a suggestion to Enforce Signatures on each policy in the Policies Summary screen
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects