Forum Discussion
Jeff_Browning_2
Jul 22, 2008Historic F5 Account
Welcome to the new Web Application Security Forum
Welcome to the new Web Application Security discussion forum newly consolidated in the Security Groups. We've created this forum as a place to post questions and discuss design, configuration, and cus...
Mike_Maher
Nimbostratus
Feb 03, 2012Nik,
So I guess that all depends on what you are asking when you say is it ok to do this.
If you are asking from an F5 configuration standpoint, I agree with Aaron that if you are learning URLs tightening would be your best option using the *.
However if you are asking from a Security standpoint, my personal opinion on tightening is that I don't do in the production environment, I do 99.9% of tightening and staging (policy building) in a controlled test environment and then copy that policy to production. I have occasionally done some very targeted staging for parameters in production and I do stage new Attack Signatures, but that is about it. Unless you can control who is hitting your site during your tightening period I would restrict it to test environment only. Just my personal opinion.
Mike
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
