Forum Discussion
Can ASM signatures be downloaded (Auto/Scheduled) from another source
We have some BIGIP LTM/ASM devices that cannot have access to the internet. Is it possible to host a non-internet connected server repository with copies of the ASM signatures and configure the ASM to automatically (Schedule) download these from this server as apposed to going direct to the F5 Download Site or manually downloading for each ASM.
- Peter_Mills_697Historic F5 Account
The next version of the BIG-IQ should be able to download and install signature updates and other incremental updates e.g. threat campaigns, whether via a proxy or direct.
- Simon_08
Nimbostratus
So currently (v13.1.0) of Bigip ASM cannot be configured for automatic updates to any other location other than the F5 download site?
- Peter_Mills_697Historic F5 Account
- Simon_08
Nimbostratus
Yes looked at this doc and only supports proxy, but no mention of configuring to download attack sigs from a customer server.
never read or heard about anyone setting that up.
if you have time to spare you can investigate how the F5 handles it with the public repository and build that yourself. add an entry in your DNS or use a virtual server on that IP to serve the requests. lots of work though, probably better to look into that BIG-IQ option.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com