Forum Discussion
Paul_Ryan_73610
Jul 06, 2011Nimbostratus
Policy Builder Modes
Hi,
Just wondering if somebody can clarify this process for me... I am running through the deployment wizard and have chosen to manuayl build the policy which will mainly be on untrusted traffic. From what I understand the manual policy uses wildcards for entities for a certain period before tightening? In which period I can clear violations as they occur and remove false positives....
Is this the correct way to build a policy?
Thanks guys
- Mike_MaherNimbostratusI think you find that policy building is more of an art than a science. You can definately do it the way you described, however the way I try and build policy is a little different. I try to get a construct of the application from my developers first, (Methods, Cookies, File Types, URLs, Parameters) then manually input those into the policy. I then use Staging on the File Types and Parameters in order to learn lengths Value Type, Data Type and so on. Optimally I prefer to get all that information up front but that is not always something they can provide easily. This process may require a little more manual work on the part of the policy admin up front, but then I don't have to have them run through their application to get all the learning suggestions worked out, and then have them test it all again after I put it in blocking mode to make sure nothing was missed.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects