Forum Discussion
mkeenan_289714
Nimbostratus
Dec 07, 2016Difference between "Illegal" and "Blocked" request
I recently accepted all learning suggestions from a security policy after confirmation from the web app developer. We took the security policy out of staging and put it into transparent mode with the...
Hannes_Rapp
Nimbostratus
Dec 07, 2016'Illegal' in the ASM logs may also mean you have checked the
Alert
tickbox in policy Blocking Settings while the Block
tickbox is unchecked. So the request is deemed illegal according to your policy configuration, but not subject to blocking (even when policy itself is in Blocking Status, you can have individual features as alert-only).
You may want to have such "alert-only" configuration for security-features you are planning to take into use, but want to first evaluate if those features align with your application without a negative consequence.
Regards,
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects