Forum Discussion
WAF Organizational Processes
my suggestion, if havent, the waf should be managed by application/application security team, instead of network security because waf config must match the characteristic of the application, e.g. request and response data spec, session persistence mechanism, etc.
same thing applies for LTM / load balancing module due to same reason.
waf config principle basically configure it as restrictive/secure as possible while still allowing legitimate access.
therefore, waf learning process should not use traffic from common users, but use traffic from designated app testers because common users may consist hackers in addition of legitimate users.
this can be done easily in f5 by using test virutal server for designated app tester then apply the verified learning result to waf policy of common users' virtual server.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com