Forum Discussion

ghost-rider_124's avatar
ghost-rider_124
Icon for Nimbostratus rankNimbostratus
Jun 23, 2014

F5 ASM Wilcard Parameter

Hello Experts

 

F5 is in manually learning mode . I made wildcard parameter and enable the tightening. I learned 10 parameters. I accept those parameters.

 

1- Should I enable the staging for all 10 parameters? What other learning suggestions, I would get?

 

2- If I enable staging in wildcard then staging would be automatic enable on learned parameters?

 

3- After learning is complete, should I delete wildcard entry and then put in block mode?

 

4- After putting in blocking mode, new parameters comes and wildcard is still there then it would allow that new parameter?

 

Thanks for reply

 

Regards,

 

GR

 

1 Reply

  • nathe's avatar
    nathe
    Icon for Cirrocumulus rankCirrocumulus

    ghost-rider,

     

    Answers to the above:

     

    1. from point 4 it sounds as if you are in transparent mode. If so then no need for staging period. Staging will only not block if the policy was set to block. transparent mode won't block so no need.

       

    2. not sure that it is

       

    3. you can do both. Yes to enable block mode if you're happy that the policy is as it should be. if you want the tighest configuration possible then do delete the wildcard entry as any parameters not explicitly defined will match this.

       

    4. yes it will do.

       

    Hope this helps,

     

    N