Forum Discussion
Re: ASM IP Exceptions
- Hello, the category that seems to be blocking the valid traffic is "Botnets", you would still recommend removing that category? or would I make adjustments on the policy learning section?
7 Replies
- Ivan_Chernenkii
Employee
Hello Crowe,
Image is not available...
If these are different IP addresses, but from the same subnet, then you can just add this subnet into Application Security : IP Addresses : IP Address Exceptions and Ignore IP Intelligence for it.
If these are totally different IP addresses, but all of them are valid - it sounds strange for me, but in this case you can disable the whole category, to not add them one by one as exception via learning.
If both case aren't good for you, then yes - proceed through the learning.
Thanks, Ivan
- crowe
Cirrus
It is strange indeed as it is always different public IP addresses being blocked, that is why we have ended up with three pages of /32 addresses in the IP exceptions list. Yesterday was the first day in two weeks since I have received a block, I'll give it more time to see if they are consistently the same category. Thank you.
The image was just the details of what I'm seeing in ASM logs regarding the latest block.
- crowe
Cirrus
Unfortuantely, the false positives are coming in under different categories. I just got a new one that is "Windows Exploits - Scanners".
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com