F5-ASM-AdvWAF-RDP(Rapid Deloyment template)(三)

1, F5 has built strategy templates, there is personal experience, the first policy uses RDP, do not ask so much why is personal experience.
Follow all policies are based on the article strategy,

2, RDP included under Soviet policy, RDP strategy is PCI-compliant (generally unpopular in this country, but many domestic standards are copied to this standard, so that a strategy to deal with some of the audit on it)

F5-ASM-AdvWAF-RDP(Rapid Deloyment template)(三)

3, the first strategy to establish personal habits as follows:
Version: V13.1.1.5
F5-ASM-AdvWAF-RDP(Rapid Deloyment template)(三)
F5-ASM-AdvWAF-RDP(Rapid Deloyment template)(三)
F5-ASM-AdvWAF-RDP(Rapid Deloyment template)(三)
F5-ASM-AdvWAF-RDP(Rapid Deloyment template)(三)

4, pay attention to the point:
although we have chosen block, but there will be a place staging, as long as the staging, even if the block is not open blocked (I just find a place elsewhere if there is not strange, after all, this is F5).
staging behind speaks alone, do fine on a step by step strategy tactics time useful.
This place staging to solitary confinement,
F5-ASM-AdvWAF-RDP(Rapid Deloyment template)(三)

5. Related log, test our log all requests, production log illegal, sent to an external log,
F5-ASM-AdvWAF-RDP(Rapid Deloyment template)(三)

6, breaking the law first Block
RDP default only supports get, post, head three kinds http method. Fiddle with a put request, and to look log
F5-ASM-AdvWAF-RDP(Rapid Deloyment template)(三)
F5-ASM-AdvWAF-RDP(Rapid Deloyment template)(三)

One reason is put request block manner;
Fiddle non browser, so it alarm

Guess you like

Origin blog.51cto.com/8525378/2429582