Forum Discussion

mrunali09_33564's avatar
mrunali09_33564
Icon for Nimbostratus rankNimbostratus
Nov 02, 2017

Changing the enforcement mode

I'm working on F5 ASM for the first time. Until now we have analysed the attack signatures and are ready to change the enforcement mode from learning to blocking. I need to know once I change this mode will the attack signatures come out of the staging?

 

  • No, it is not automatic. For ASM to enforce the signatures on traffic (block if a violation occurs) 3 settings must be configured properly:

     

    1. Your security policies enforcement mode must be set to Blocking
    2. The attack signatures must be set to Block on the Blocking Settings list (the learn/alarm/block checkboxes)
    3. Staging must be disabled on the signatures (also known as enforcing the signatures)