Forum Discussion

Sunil_Yadav_91's avatar
Sunil_Yadav_91
Icon for Nimbostratus rankNimbostratus
Mar 07, 2024

Need to add multiple scanner IP to ASM policy

Hello Team,

 

In our environment we have onboarded 40+ application on F5 ASM WAF and for all application we have created individual security policy but now there is one requirement, we need to whitelist multiple Scanner IP from ASM policy, so if i will add each IP manually then it will be very time consuming task.

 

So if i create parent policy and add all IP in IP exception so can it will work if i add all security policy as child policy ?

is there any Impact because we have performed multiple changes in security policy as per application requirement and we do not want to touch those changes.

 

 

Sunil

1 Reply

  • To: avinasheokumar1@DogNeedsBest

     

    So if i create parent policy and add all IP in IP exception so can it will work if i add all security policy as child policy ?

    is there any Impact because we have performed multiple changes in security policy as per application requirement and we do not want to touch those changes.

    You can create an IP type LTM data-group and define the allowed IP/subnet values. Then you can use an iRule to check the source IP address of the incoming traffic against the data-group and allow or block it accordingly.