Forum Discussion

Stack_Smash's avatar
Stack_Smash
Icon for Nimbostratus rankNimbostratus
May 24, 2018

Traffic interruption by ASM policy exchange?

Hello,

 

I need to exchange some existing ASM policies. Some are modifiable via the security options section of the virtual server, some need to be changed by creating a draft of an L7 policy (auto asm policy) and publishing it (security options section shows "Manual Configuration").

 

Does any of these two methods interrupt traffic?

 

Thanks in advance, Kind regards

 

2 Replies

  • Hi,

     

    F5 ASM don't interrupt traffic therefore you need to be careful about type of policy. Because some kind of policy are in blocking mode. And can impact production by blocking legitimate traffic...

     

    let me now if you need details.

     

  • With regard to transparent policies, there can be an impact on traffic if you are using threat mitigations which mask characters (Data Guard), or inject JavaScript into an HTTP response including brute force protection, bot defense, web scraping, persistent device tracking, and L7 DoS protection. There will be activity associated with these defenses even if the policy is transparent mode--remember that a DoS profile for example, works with or without an ASM policy.