Forum Discussion
UNABLE TO LEARN SOME REQUEST VIOLATION IN BIGIP ASM 12.1.0
I am using BIGip ASM version 12.1.0. I have configured virtual servers & blocking policies on those virtual servers . I am able to learn requests for some violations but for some violations I am not able to learn suggestions in Security-->APPLICATION security-->policy building-->traffic learning but the same requests can be seen in security-->eventlogs-->applictaion-->request. Since I am not able to learn suggestion for this request I am not able to accept or ignore violation.
Please help me if it is a bug or known issue in BigIP 12.1.0
6 Replies
- PeteWhite
Employee
Can you give us an example please - there are some violations that cannot be learned such as HTTP header errors. Violations related to file types, URLs, parameters etc should have learning suggestions.
- Deepti_Nayak_26
Nimbostratus
I couldnot learn violations for HTTP protocol compliance(Null Request),failed to convert character.
- Deepti_Nayak_26
Nimbostratus
I couldn't learn violations for HTTP protocol compliance(Null Request),failed to convert character.
- Deepti_Nayak_26
Nimbostratus
I couldn't learn violations for HTTP protocol compliance,failed to convert character.
- Deepti_Nayak_26
Nimbostratus
http compliance protocol ,failed to convert character
- samstep
Cirrocumulus
Deepti, these violations are not learnable, you will need to add them manually to the policy.
The following violations are considered unlearnable:
- Request length exceeds defined buffer size
- CSRF authentication expired
- Illegal session ID in URL
- Login URL bypassed
- Login URL expired
- Cookie Violations
- ASM Cookie Hijacking
- Expired timestamp
- Modified ASM cookie
- Input Violations
- Illegal number of mandatory parameters
- Failed to convert character
- Brute Force: Maximum login attempts are exceeded
- Null in multi-part parameter value
- Negative Security Violations
- Virus detected
- RFC Violations
- Cookie not RFC-compliant
These are other special violations for which the system does not provide learning suggestions:
- Access from disallowed User/Session/IP
- Web scraping detected
Hope this helps,
Sam
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com