Technical Forum
Ask questions. Discover Answers.
cancel
Showing results for 
Search instead for 
Did you mean: 

Alert and pass the traffic when the policy is in blocking mode for violation rating 1 or 2

Dayal
Nimbostratus
Nimbostratus

Hi Team,

 

I have ASM deployed in the network and have a dynamic website behind the same. I am bombarded with many violations with ratings 1 and 2 which the F5 suggests likely a false positive. Is there a way that I can allow the violations which have ratings 1 or 2 to pass through but at the same time provide an alert ?

 

Thanks,

 

5 REPLIES 5

Tikka_Nagi_1315
Historic F5 Account

You would have to configure the security policy to not Alarm under Enforcement Mode.

 

It can be achieved by configuring blocking actions for violations under:

 

Security > Application Security > Blocking.

 

https://support.f5.com/kb/en-us/products/big-ip_asm/manuals/product/asm-implementations-11-5-0/24.ht...

 

Michael_Michael
Nimbostratus
Nimbostratus

Hi, i also wonder if it posible to pass violatio 1 and 2. lots of FP. Please advice.

 

I would recommend that you open a support case and provide an asmqkview --add-request-log for F5 to review the potential false positives.

 

Michael_Michae1
Nimbostratus
Nimbostratus

Hi, i also wonder if it posible to pass violatio 1 and 2. lots of FP. Please advice.

 

I would recommend that you open a support case and provide an asmqkview --add-request-log for F5 to review the potential false positives.