I create Attack signature and still in staging although I change it to blocking
Hi I have create attack signature which block the request if it is containing some words. the status of my signature is : Staging: No Learn: Yes Alarm: Yes Block: Yes Enabled: Yes What i dont understand is : when i try to access the blocked link i still can access it And when i go to : Security > Event Logs > Application > Requests F5 see it as an attack but in the status of "Applied Blocking Settings" is still Staged? The Enforcement Mode of my policy is : Blocking708Views0likes1CommentASM attack signature false positive
Hi, I have 2 application; one of them run on F5-ASM which is AA and other one not which is BB. BB try to connect AA for some data, but ASM blocked and I could not see any support ID. When i uncheck the attack signature everything is ok. Any idea? Can I uncheck the signature for specific source host.174Views0likes1CommentGet rid of log requests from geo IP blocking
Our ASM log gets flooded with requests blocked from Geo IP blocking filter. This makes it hard to find important log events. I have not found any way to get rid of these alerts: In the blocking settings: We are now on version 12 hf2 but it has been the same since version 11.6. These alerts are also sent to remote log even though it's set to not alarm. Please advice.243Views0likes1Comment