Forum Discussion
Disable Attack Signature on Hostname
I think I already know the answer ( create a separate ASM policy ) but thought I would ask the more knowledgeable people out there.
I have a large amount of sites on my F5 ASM/LTM device so I have tried to group like sites in ASM policies together, this works generally fairly well.
However, I have one site in my catch all policy that is triggering a particular attack signature that I want to disable for that site ( i.e, disable via hostname ). Is there anyway possible to do this ? The attack signature itself is 200001579, formaction(Parameter) so turning it off at the parameter lever ( formaction ) is the same as turning it off globally.
So apart from creating a new policy for just that one site, is there any alternatives ?
F5 version is 11.5.1 HF7.
Dan
1 Reply
- Max_Q_factor
Cirrocumulus
Have you looked into an ASM iRule? Here is a devcentral question about it https://devcentral.f5.com/questions/disable-specific-asm-attack-signatures-on-specific-url
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com