Forum Discussion

smalex's avatar
smalex
Icon for Altostratus rankAltostratus
Mar 29, 2018

HTTP Profile linking for ASM

I am new to F5. We have got ASM license and need to implement them. Some of our live virtual servers do not have a http profile linked to it. I understand http profile needs to be linked if asm has to be implemented. Can I go ahead and blindly go ahead with deafult http profile linking? Will there be any production impact? If so, what are things that should be checked/kept in mind before doing so?

 

I do see SSL Profile (Client) and SSL Profile (Server) attached to virtual server. Does this mean there would be issues if I attach the http profile?

 

Does changing or implementing http profile require downtime?

 

1 Reply

  • nathe's avatar
    nathe
    Icon for Cirrocumulus rankCirrocumulus

    smalex,

     

    The default http profile is normally sufficient and it's good to see that you are decrypting the traffic (clientssl) as this is also a pre-req for ASM inspection (and the http profile as well). I'm not sure anyone can guarantee that there would be no issues with "blindly" adding the profile. Best practice to do this in a Change window and/or on non-production VIPs.

     

    Good luck, hope this helps.

     

    N