Applies To:
Show VersionsBIG-IP ASM
- 13.0.1, 13.0.0
Overview: Creating parent and child security policies
You can use Application Security Manager™ (ASM) to create two layers of security policies: parent policies and child policies. Parent policies include mandatory policy elements, and child policies inherit those attributes from the parent. When the parent policy is updated, its child policies are automatically updated.
Parent policies let you
- Create and maintain common elements and settings
- Impose mandatory elements on child policies
- Push a change to multiple child policies
You can specify which parts of the security policy must be inherited, which are optional, and which are not inherited. This way, you can keep child policies in sync with the changes in the global mandatory policies and still allow the child policies to address their own unique requirements. The inheritance follows the sections of the policy in the Learning and Blocking Settings: each part can be inherited or not inherited from the parent.
Creating a parent security policy
Configuring parent policy settings
Creating a child security policy
The security policy immediately starts protecting your application. The enforcement mode of the security policy is set to Blocking. Traffic that is considered to be an attack such as traffic that is not compliant with HTTP protocol, has malformed payloads, uses evasion techniques, performs web scraping, contains sensitive information or illegal values is blocked. Other potential violations are reported but not blocked.
If the parent is changed, the child policy is automatically updated with the latest inherited (or accepted) settings.
Reviewing learning suggestions for parent and child policies
After you create parent and child policies and begin sending traffic to the application protected by the child policy, the system provides learning suggestions concerning additions to the policies based on the traffic it sees. For example, you can have users or testers browse the web application. By analyzing the traffic to and from the application, Application Security Manager™ generates learning suggestions or ways to fine-tune the parent and child policies to better suit the traffic and secure the application.
Suggestions related to settings that are inherited appear locked in the child policy and can only be accepted in the parent policy.