Forum Discussion

AhmedSaied_2402's avatar
AhmedSaied_2402
Icon for Altostratus rankAltostratus
Aug 26, 2018

which login page can defined in case using APM with ASM

which login page can be defined in ASM policy on exchange if I am using APM and login URL appear as

 

should we use my.policy ?!

 

also is there any way to change this url

 

2 Replies

  • Hi Ahmed,

     

    You right it's

     

    But keep in mind that APM it execute before ASM. So if you set your VPE (apm Policy) and (ASM policy) on the same VS, ASM will not trigged an attack on your page (brute force for example).

     

    If you want to protect your APM Page, you have to create 2 VS:

     

    • First VS: set your asm policy and set an LTM Policy to FW flow in the second VS
    • Second VS: set your APM Policy (this vs have also your excahnge configuration ...).

    can you explain me why you want to set asm protect your APM Page? if it's for brute force , you can do it easly with APM. You have an Macro in VPE that treat this need.

     

    Keep me update.

     

    Regards

     

  • You don't need to configure login / logout page on ASM if you use the APM. As ASM process the requests after the APM, the ASM won't see them anyway. You should enable session tracking specific to APM under

    ASM / Application Security : Sessions and Logins : Session Tracking
    and then select
    Session Awareness = enabled
    ,
    Application username=use APM Usernames and Session ID