Forum Discussion
mrunali09_33564
Nimbostratus
Nov 02, 2017Changing the enforcement mode
I'm working on F5 ASM for the first time. Until now we have analysed the attack signatures and are ready to change the enforcement mode from learning to blocking. I need to know once I change this mode will the attack signatures come out of the staging?
- gsharri
Altostratus
No, it is not automatic. For ASM to enforce the signatures on traffic (block if a violation occurs) 3 settings must be configured properly:
- Your security policies enforcement mode must be set to Blocking
- The attack signatures must be set to Block on the Blocking Settings list (the learn/alarm/block checkboxes)
- Staging must be disabled on the signatures (also known as enforcing the signatures)
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects