Forum Discussion
Merging two policies with conflicting settings.
Hi;
When I merge a policy2 with Enforcement Mode of block and disabled signature staging with policy1 with Enforcement Mode of transparent and enabled signature staging. The merging is to be Automatic with maintaining the conflicting settings on each policy.
What would be the resultant setting here?
would it be transparent/staging enabled? My working colleague is telling me it is Blocking/staging enabled.
Kindly Wasfi
1 Reply
- Chris_Grant
Employee
Because these are both global settings you can't have a mix and match. Any time you merge policies you should review the resulting policy for potential problems. Our documentation on this is very old, but it appears that if either policy has staging enabled, staging will be enabled on the attack signatures in the new policy. Some decisions depend on which is the primary policy and which is the secondary, and it is not clear if the global blocking setting is one of these. I would not say that your findings are unexpected, though.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com