Forum Discussion

jerm1020_254086's avatar
jerm1020_254086
Icon for Nimbostratus rankNimbostratus
Aug 21, 2016

How to best address signature tripping and exception list

I am looking for an answer on how to best address signature tripping and exception list; do we disable base signature, create custom signature inheriting from base, adjust it to allow legit traffic but block all else. we have some scanners in the internal network and want to allow only these certain IPs or domains to scan. how would I go about addressing this?

 

1 Reply

  • i asume you are talking about ASM here?

     

    the first part i don't quite understand. with ASM you use ASM policies, per policy you can disable certain attack signature you don't want.

     

    those scanners should not be blocked at all? there is the IP exception list for that.

     

    Security ›› Application Security : IP Addresses : IP Address Exceptions