Forum Discussion
What is the maximum count of entities can asm policy have?
What is the maximum count of entities can asm policy have? is there a limit or it's unlimited?
...version 12.1.2 i mean url entites
This is undocumented so I had to test. Used VIM to create a ton of dummy
, and imported ASM policy as XML. No problems encountered at 5312 (when I stopped my tests). In practice, it's highly unlikely anything less than 8192 is the limit. Regardless of the exact number, this is more than enough. You never define more than around 100 Allowed URLs per policy. Even at 50 URLs it makes sense to use some wildcards. After 100, it makes sense to turn the tables and go with a negative security model (you define what is NOT allowed)Allowed URLs
For reference, my test Screenshot
- Hannes_RappNimbostratus
This is different across entities, and also different across BigIP ASM software versions. What version and what entity in particular?
- yosry92_331999Nimbostratus
version 12.1.2 i mean url entites
- Hannes_Rapp_162Nacreous
...version 12.1.2 i mean url entites
This is undocumented so I had to test. Used VIM to create a ton of dummy
, and imported ASM policy as XML. No problems encountered at 5312 (when I stopped my tests). In practice, it's highly unlikely anything less than 8192 is the limit. Regardless of the exact number, this is more than enough. You never define more than around 100 Allowed URLs per policy. Even at 50 URLs it makes sense to use some wildcards. After 100, it makes sense to turn the tables and go with a negative security model (you define what is NOT allowed)Allowed URLs
For reference, my test Screenshot
- yosry92_331999Nimbostratus
thank you
- Hannes_RappNimbostratus
...version 12.1.2 i mean url entites
This is undocumented so I had to test. Used VIM to create a ton of dummy
, and imported ASM policy as XML. No problems encountered at 5312 (when I stopped my tests). In practice, it's highly unlikely anything less than 8192 is the limit. Regardless of the exact number, this is more than enough. You never define more than around 100 Allowed URLs per policy. Even at 50 URLs it makes sense to use some wildcards. After 100, it makes sense to turn the tables and go with a negative security model (you define what is NOT allowed)Allowed URLs
For reference, my test Screenshot
- yosry92_331999Nimbostratus
thank you
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com