Forum Discussion
IP Address Exception: How does a policy manage conflicting exceptions
Goal: For 10.0.0.0/8 range - Do not block (can add IP Address Exception for ASM Policy) - Learn (Can note learning in IP Exception setup) - BUT, for specific 20 IP in 10.0.0.0/8, Turn OFF learning (but do not block) as allowed vulnerability scanner. Unsure how asm policy would manage if exceptions conflict. Any suggestions for implementing this scenario? Thank you.
- Simon_Blakely
Employee
From the help notes for ASM IP Address Exceptions
Note: If an IP address belongs to more than one range (using netmasks) so that there are overlapping IP address ranges, and one IP address is configured as Enabled on any setting on this screen, while another is configured as Disabled, the Enable action takes priority over the Disable action.
- Check1t_282465
Nimbostratus
Thanks for the clarification.
if you feel it was the correct answer please flag it as such.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com