Forum Discussion

Check1t_282465's avatar
Check1t_282465
Icon for Nimbostratus rankNimbostratus
Nov 16, 2017

IP Address Exception: How does a policy manage conflicting exceptions

Goal: For 10.0.0.0/8 range - Do not block (can add IP Address Exception for ASM Policy) - Learn (Can note learning in IP Exception setup) - BUT, for specific 20 IP in 10.0.0.0/8, Turn OFF learning (but do not block) as allowed vulnerability scanner. Unsure how asm policy would manage if exceptions conflict. Any suggestions for implementing this scenario? Thank you.

 

3 Replies

  • From the help notes for ASM IP Address Exceptions

     

    Note: If an IP address belongs to more than one range (using netmasks) so that there are overlapping IP address ranges, and one IP address is configured as Enabled on any setting on this screen, while another is configured as Disabled, the Enable action takes priority over the Disable action.