Forum Discussion

jafar201_133847's avatar
jafar201_133847
Icon for Nimbostratus rankNimbostratus
Sep 17, 2013

ASM in learning mode issues

Greeting we are facing a strange issue since 3 days a go when Security team start F5 ASM in learning Mode user Start complaining from unusual Slowness and Odd behavior , some User report that they are been redirect to the login page once they are trying to login other reported This page can't be displayed error this only started to happened since Security put ASM in training mode

 

we use F5 as load balance IP based and we are using Form authentication Asp.net 4.5 IIS7 . if any one have any Idea of what is wrong or what Could be the reason I would be Most grateful

 

thanks

 

2 Replies

  • The first thing I would do is remove the HTTP Class profile that ties ASM to the virtual server (9.x to 11.3) or common policy in 11.4 and see if the behavior persists.

     

    At first glance I'm not sure ASM is the culprit. ASM by default will not redirect a user to the logon page, it will typically respond with a block page.

     

    As for the "This page can't be displayed", this may be caused by a TCP reset (RST) packet being sent from the backend server. You can view SOL13223 to see to configure F5 to log the reset reason.

     

  • I agree with Cody...here are a few other things to consider: the ASM won't actually block on anything while the security policy is in Transparent mode...it only starts blocking when you configure the Blocking Settings and put it in Blocking mode. Also, the default ASM reject page lists a reject notice along with a support ID number. You can configure the ASM to automatically redirect to a different URL upon a request reject, but if you just set up the ASM and didn't touch the response page configuration, it won't redirect.

     

    I hope this helps clarify at least part of your issue!