
Learn to build a positive security policy for web apps by defining explicit file types, URIs, and parameters, with wildcards and learning modes never, always, selective, and come back.
Explore building a positive security policy via enforcement readiness and staging, learning entities from traffic, and refining rules with traffic learning to prevent false positives.
Learn how cookies and headers are secured through an application security policy, including signed and infused cookies, allowed versus enforced keys, and tamper detection with digests and signatures.
Explore Aasim reporting, featuring an overview with customizable graphical reports and a reporting section with filters, widgets, and the ability to export PDFs or send emails.
Explore how the WAF logs system and administrative events locally, view logs via GUI or CLI, and configure logging profiles to filter traffic and forward data to a remote server.
Configure a logging profile for local and remote UDP logging, attach it to the virtual server's security policy, enable blocking, and verify logs after enabling send content events.
Enable and verify response logging in the F5 WAF by creating a response logging profile, attaching it to a security policy, and testing with application requests to see logged responses.
Learn to protect static parameters by defining allowed values, applying a security policy, and enforcing blocking for illegal static parameter values in payment parameters.
Learn how to protect dynamic parameters with extraction rules, dynamic barometer values stored in a DCB frame cookie, and blocking policies that detect tampering and enforce illegal dynamic parameter values.
Explore parameter levels in web apps—global, user-level, and flow parameters—and how security policies enforce static, dynamic, and sensitive values from most to least specific.
Use policy depth to compare two security policies across production and staging, identify differences in language, protocol, and sensitivity, and merge or export changes with copy, original, or make-a-copy modes.
Compare two security policies, merge differences with automator, export as XML, edit settings (blocking mode, max header length, remove response codes), and re-import as the updated policy.
Explore Aasim deployment types, from standalone appliances to LTM-backed and multi-device clusters, for scalable web application protection. Learn about span monitoring, device groups, and synchronization for reliable policy enforcement.
The Application Security Manager course gives participants a functional understanding of how to deploy, tune, and operate Application Security Manager (ASM) to protect their web applications from HTTP-based attacks.
The course includes lecture, hands-on labs, and discussion about different ASM components.
In this course we will be discussing below topics:
Approach towards building a positive security policy.
Securing Cookies and other headers.
Reporting and Logging Functionalities on ASM.
Static and Dynamic Parameter Handling
Comparing Security Policies
ASM deployment types