Sep 25, 2023

In an active/standby setup of ASM, with sync only device group, do signature updates sync up?

In an active/standby setup of ASM or AWAF, let's say we added the sync-only device group to synchronise any automatic policy changes. Would updating the attack signatures on the active device propagate to the standby device?
  • quangtran's avatar
    Sep 25, 2023

    Hi Wasfi_Bounni 

    Configuring signature updates between two devices is independent, so I believe updating should be done manually on the standby device.

  • ragunath154's avatar
    Sep 26, 2023

    When you set up ASM™ synchronization, in addition to security policies, other settings such as custom attack signatures, logging profiles, SMTP configuration, anti-virus protection, system variables, and policy templates, are synchronized with all devices in the ASM-enabled device group.

    If Attack Signatures Update Mode is scheduled for automatic update, the attack signature update settings are synchronized(not signatures). Each device in the device group updates itself independently according to the configured schedule. If you manually upload attack signatures or click Upload Signatures to update from the server, the update is propagated to all of the devices in the device group.