Forum Discussion

Deepti_Nayak_26's avatar
Deepti_Nayak_26
Icon for Nimbostratus rankNimbostratus
Oct 14, 2016

UNABLE TO LEARN SOME REQUEST VIOLATION IN BIGIP ASM 12.1.0

I am using BIGip ASM version 12.1.0. I have configured virtual servers & blocking policies on those virtual servers . I am able to learn requests for some violations but for some violations I am not able to learn suggestions in Security-->APPLICATION security-->policy building-->traffic learning but the same requests can be seen in security-->eventlogs-->applictaion-->request. Since I am not able to learn suggestion for this request I am not able to accept or ignore violation.

 

Please help me if it is a bug or known issue in BigIP 12.1.0

 

6 Replies

  • Deepti, these violations are not learnable, you will need to add them manually to the policy.

     

    See ASM Configuration Guide:

     

    The following violations are considered unlearnable:

     

    • Request length exceeds defined buffer size
    • CSRF authentication expired
    • Illegal session ID in URL
    • Login URL bypassed
    • Login URL expired
    • Cookie Violations
    • ASM Cookie Hijacking
    • Expired timestamp
    • Modified ASM cookie
    • Input Violations
    • Illegal number of mandatory parameters
    • Failed to convert character
    • Brute Force: Maximum login attempts are exceeded
    • Null in multi-part parameter value
    • Negative Security Violations
    • Virus detected
    • RFC Violations
    • Cookie not RFC-compliant

    These are other special violations for which the system does not provide learning suggestions:

     

    • Access from disallowed User/Session/IP
    • Web scraping detected

    Hope this helps,

     

    Sam

     

  • Can you give us an example please - there are some violations that cannot be learned such as HTTP header errors. Violations related to file types, URLs, parameters etc should have learning suggestions.

     

  • I couldnot learn violations for HTTP protocol compliance(Null Request),failed to convert character.

     

  • I couldn't learn violations for HTTP protocol compliance(Null Request),failed to convert character.

     

  • I couldn't learn violations for HTTP protocol compliance,failed to convert character.