Forum Discussion

CDG's avatar
CDG
Icon for Nimbostratus rankNimbostratus
Apr 25, 2016

ASM Loading , Receiving configuration data from your device.

Im trying to create a Security Policy (ASM) but the creation hang.....Loading , Receiving configuration data from your device. Any help would be appreciated. Where should I look to find what is blocking the configuration process?

 

Security Policy Configuration Summary

 

Attack Signatures Configuration SystemsGeneral Database, Various systems, All systems, Microsoft Windows, BEA Systems WebLogic Server

 

Signature SetsAutomatically assigned set(s): Generic Detection Signatures

 

Following set will be created: Systems: Microsoft Windows, BEA Systems WebLogic Server

 

Signature StagingEnabled

 

Automatic Policy Building Configuration

 

Policy TypeFundamental

 

RulesPolicy Builder learning speed: Medium

 

Chance of adding false entities to the policy: Medium

 

Trusted IP AddressesN/A

 

Enable AJAX blocking response behaviorNo

 

5 Replies

  • Charles_Rosenbe's avatar
    Charles_Rosenbe
    Historic F5 Account

    You don't mention which version-hotfix you are running. Depending on that, there could be known bugs or other issues.

     

    In general, you can look for GUI issues in

     

    /var/log/httpd/httpd_errors

     

    /var/log/tomcat/catalina.out

     

    or general errors will be in

     

    /var/log/asm

     

    /var/log/ltm

     

    I recommend taking a qkview and uploading it to iHealth to get some basic Heuristics run to see if there isn't something that it can catch. It usually is a good starting point for some of the more common issues.

     

  • CDG's avatar
    CDG
    Icon for Nimbostratus rankNimbostratus

    Thanks Charles.... Im running Running BIG-IP 11.5.1 Build 4.0.128 Hotfix HF4

     

    I get this in httpd_errors

     

    err httpd[7920]: [error] server reached MaxClients setting, consider raising the MaxClients setting

     

    What would be the best practice numbers for the MaxClients setting?

     

    • CDG's avatar
      CDG
      Icon for Nimbostratus rankNimbostratus
      https://support.f5.com/kb/en-us/solutions/public/9000/500/sol9588.html As per this article...I set the MaxClients Setting to 20.
  • CDG's avatar
    CDG
    Icon for Nimbostratus rankNimbostratus

    Well my problem is not related to the creation a policy. Even if I try to do an attack signature update after few minutes a get kick out from the Configuration utility (Unable to contact BIG-IP device). I have to do a restart /sys service httpd to get the configuration utility back and running.

     

    I will open a support case on this.

     

    • Charles_Rosenbe's avatar
      Charles_Rosenbe
      Historic F5 Account
      That is probably going to be the best route. Just for reference, are there multiple users administering the device? Or, are you using a 3rd party tool to manage it? How about the iControl REST API? Or the older iControl XML/SOAP-based one?