Manual Chapter : Per-Request Policy Maintenance

Applies To:

Show Versions Show Versions

BIG-IP APM

  • 17.0.0, 16.1.5, 16.1.2, 16.1.1, 16.1.0
Manual Chapter

Per-Request Policy Maintenance

Customizing messages for the per-request policy Reject ending

You need an access profile configured.
Customize the messages to display when a per-request policy terminates on a Reject ending. When this happens, the per-request policy triggers the access profile Logout screen.
  1. On the Main tab, click
    Access
    Profiles / Policies
    Customization
    General
    .
    The Customization tool appears in General Customization view, displaying
    Form Factor: Full/Mobile Browser
    settings.
  2. In the left pane, select the
    Text
    tab.
    A navigation tree displays in the left pane.
  3. Expand the
    Access Profiles
    folder.
    Folders for access profiles that are configured on the BIG-IP system in the current partition display.
  4. Expand the folder for access profile that you want to update.
    Folders for access profile objects display.
  5. Expand the
    Logout
    folder for the access profile.
    The
    General
    setting displays in the folder.
  6. Click
    General
    .
    Message settings display in the right pane.
  7. In the right pane, update values.
  8. On the menu bar, click
    Save
    .
  9. Click the
    Apply Access Policy
    link to apply and activate the changes to the policy.
  10. On the list of access profiles to apply, verify that the access profile that you updated is selected.
  11. Click the
    Apply Access Policy
    button.

Exporting and importing a per-request policy across BIG-IP systems

Export a per-request policy from one BIG-IP system and import it on another (at the same product version level) to copy a policy across systems.
Per-request policy import does not support the import of custom categories or the URLs defined for them. Before you import a per-request policy from one BIG-IP system to another BIG-IP system, you must first list any custom categories configured on the source system and make sure you have the same custom categories on the target system. Otherwise, import will fail.
  1. On the Main tab, click
    Access
    Profiles / Policies
    Per-Request Policies
    .
    The Per-Request Policies screen opens.
  2. Click the link in the
    Export
    column for the policy that you want to export.
    A file downloads.
  3. Note the list of custom categories:
    1. Click
      Access Policy
      Secure Web Gateway
      URL Categories
      .
    2. Expand the Custom Categories list.
  4. Log in to the Configuration utility on the BIG-IP system where you want to import the per-request policy.
  5. Verify that the custom categories that exist on the other BIG-IP system also exist on this BIG-IP system:
    1. Click
      Access Policy
      Secure Web Gateway
      URL Categories
      .
    2. Expand the Custom Categories list.
    3. Create any additional custom categories needed to match the list on the other BIG-IP system.
      The import process does not add URLs to custom categories. To include the URLs defined for a custom category on the source system, you can add them to the target system now or wait until after you import the per-request policy.
  6. On the Main tab, click
    Access
    Profiles / Policies
    Per-Request Policies
    .
    The Per-Request Policies screen opens.
  7. Click
    Import
    .
    An Import Policy screen displays.
  8. In
    New Policy Name
    , type a name.
  9. For
    Config File Upload
    , click
    Browse
    , locate and select the file downloaded from the other BIG-IP system.
  10. To reuse objects already existing on this BIG-IP system, select the
    Reuse Existing Objects
    check box.
  11. Click
    Import
    .