Updated Date: 07/07/2026
Create a protocol inspection profile
A protocol inspection profile collects rules for protocol inspection using pre-installed signatures defined by the Snort project, or custom signatures defined using the Snort syntax. Signatures are selected and added to the profile by Service, and you can narrow the scope of signatures by a number of other characteristics. You can enforce signatures, compliance items, or both.
-
On the Main tab, click Security > Protocol Security > Inspection Profiles.
The Inspection Profiles screen opens.
-
Click Add and select New.
Alternatively, copy an existing inspection profile by selecting the profile and clicking Add, then Clone Existing.
-
Type a profile name, and optionally add a description.
-
From the Signatures menu, select Enabled to enforce signatures.
If you are enforcing only Signature items, you can select Disabled for compliance items.
-
From the Compliance menu, select Enabled to enforce compliance items.
If you are enforcing only Compliance items, you can select Disabled for signatures.
-
To collect AVR stats, from the AVR Stats Collect menu, select Enabled.
-
From the Services menu, select the services you want to add to the inspection profile.
Each selected service type displays as a new category at the bottom of the screen. By default, all inspection items are disabled. You must enable items or categories you want to inspect.
-
From Auto Approval Trigger, configured the thresholds to automatically approve suggestions. You can choose either a time based threshold between 720-43200 minutes, or a confidence based threshold, between 0% and 100%. Only one threshold can be configured, enter
0to disable the unused threshold.Note: Confidence indicates the degree to which BIG-IP AFM calculates false positives for a signature based on traffic analysis. A high percentage indicates a low false positive risk and a low percentage indicates a high false positive risk.
-
To enable inspections in the service, click the service category name on the screen.
The service category expands to show the inspections.
-
To enable an inspection, select the checkbox for the inspection.
The Edit Selected Inspections panel opens on the right of the screen.
-
To enable an inspection, select Enable, and click Apply.
-
To change the action for the selected inspection, from the Action menu select Accept, Reject, or Drop.
-
To select whether the inspection item is logged, from the Log menu select Yes or No.
Note: You can select and edit multiple inspections at once. You can select the checkbox at the top of the category to select and edit all inspections in the category.
-
When you have finished adding services and editing inspections, click Commit Changes to System.
The Inspection Profiles screen appears and the inspection profile you created is displayed in the list.
You can attach a protocol inspection profile to a firewall rule or to a virtual server.