Forum Discussion

Jaime_S_Beckman's avatar
Jaime_S_Beckman
Icon for Nimbostratus rankNimbostratus
Mar 03, 2017

ASM Policy Configuration - Allowed URLs

We have been using ASM to block our web apps for about 4 months. Recently, we started having frequent and random f5 failovers. We have been told that it is because we are using wildcard for HTTP and HTTPS in the URL: Allowed URLs portion of our policies. We are not learning, alarming or blocking Illegal URL and based on documentation provided by f5, using the wildcard is acceptable and results in a "policy that easy to manage but may not be as strict."

 

Anybody experienced this or know if it is required to have an explicit list of allowed URLs and associated Content Type profiles?

 

We are on version 12.1.2

 

1 Reply

  • nathe's avatar
    nathe
    Icon for Cirrocumulus rankCirrocumulus

    Jaime, wildcards on URLs are perfectly acceptable and you do not have to explicitly allow any. I don't understand the link between this configuration, which is the one I see most often btw, and the failover.

     

    I would check logs around the time of failover and upload qkview to ihealth too.

     

    N