Mar 27, 2026 - For details about updated CVE-2025-53521 (BIG-IP APM vulnerability), refer to K000156741.

Forum Discussion

dani_martinez_2's avatar
dani_martinez_2
Icon for Nimbostratus rankNimbostratus
May 28, 2018

Generic security Policy for All Virtual Servers

Is there the possibility to create a unique ASM Security Policy and assign that policy to a bunch of Virtual Servers? I mean like a common Policy for all of them, once they virtual servers are created that policy is assigned to them

 

1 Reply

  • Hi,

     

    An asm policy is usually dedicated for an specific application (because each application has specifities: OS, DB, language, ...).

     

    If you affect the same policy to all your application you risk having a lot of false positives. and high security risks.

     

    the disadvantages are as follows:

     

    • hard to maintain.
    • false positives.
    • white listing will impact other application.
    • release an blocage will impact other application.
    • ...

    I advise you to create a unique policy by application however you can create a generic template and use it for deploying all your application...

     

    let me now if you need more details.

     

    regards,