Forum Discussion

sk_330490's avatar
sk_330490
Icon for Nimbostratus rankNimbostratus
Jul 16, 2018

Signature sets precedence for ASM Policy

Had a query on signature sets on ASM Policy. In my Policy Attack Signature Configuration, i can see multiple groups based on which i can select either to learn, alarm or block. Basically i want to tune my policies as all of the signature sets are currently on block mode. If i want to disable just the OWA Signatures and set it to Alarm only. Should i be disabling block for "All Signatures" as well and select Attack specific signatures sets. Will enabling block for "All signatures" override the "OWA signatures" Learn only setting? Wanted to know the precedence of applying signature based checks.

 

 

1 Reply

  • nathe's avatar
    nathe
    Icon for Cirrocumulus rankCirrocumulus

    sk, signatures may be in more than one Set. If you want to tune then suggest the policy is in Transparent mode, as this overrides Blocking configuration on the attack signatures (as well as other violations too I might add).