Forum Discussion
crowe
Cirrus
Jun 23, 2020ASM IP Exceptions
We are new to having ASM implemented on our main virtual servers, over the past couple months I keep having to add IP exceptions for for valid customer IP's that get blocked as "malicious". I assume ...
- Jul 02, 2020
You need to leave Alarm enabled for malicious IP - in such case you will have ability to monitor how it works and detect (but not prevent) possible attack
crowe
Cirrus
Jun 30, 2020
- Hello, the category that seems to be blocking the valid traffic is "Botnets", you would still recommend removing that category? or would I make adjustments on the policy learning section?
Ivan_Chernenkii
Employee
Jul 02, 2020Yes, it really looks strange...
- Are you sure that all detected malicious IP are false-positive?
- Do you have any malicious IP, which is blocked correctly?
- Why it was suggested to enable malicious IP detection? What was the reason?
If there was no exact reason and you didn't get any real malicious IP for a long time, then I suggest to disable Block flag per violation (leave Alarm flag enabled for monitoring) or at least disable Block flag for each category, which provides false-positive.
Thanks, Ivan
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects