Forum Discussion
ltwagnon
Feb 24, 2015Ret. Employee
GreeceMonkey, this is a great question!
While there is no "one size fits all" answer to this, I have found it's easier to let the policy build automatically so that you don't miss anything (parameters, URLs, etc). That said, here's an article I wrote on policy building and there's some good discussion at the bottom that might help a little bit with this: https://devcentral.f5.com/articles/the-big-ip-application-security-manager-part-2-policy-building.
I hope this helps! John