# Community CodeShare

**URL:** https://community.f5.com/c/articles/codeshare/15.md

[Latest](https://community.f5.com/latest.md) · [Categories](https://community.f5.com/categories.md) · [Tags](https://community.f5.com/tags.md)

---

## [About the Community CodeShare category](https://community.f5.com/t/about-the-community-codeshare-category/69)

<div class="topic-metadata">

**Author:** [@system](https://community.f5.com/u/system)\
**Replies:** 0\
**Last updated:** [June 10, 2026, 11:46pm UTC](https://community.f5.com/t/about-the-community-codeshare-category/69 "2026-06-10T23:46:33Z")

</div>

Where the community shares working code, scripts, automations, integrations, and other reusable solutions for the benefit of all. Use this space to contribute iRules, automation scripts, APIs, integrations, templates, u…

---

## [UDP TCP Packet Duplication](https://community.f5.com/t/udp-tcp-packet-duplication/64437)

<div class="topic-metadata">

**Author:** [@Ken\_Bocchino\_49](https://community.f5.com/u/Ken_Bocchino_49)\
**Replies:** 40\
**Last updated:** [September 30, 2026, 6:39pm UTC](https://community.f5.com/t/udp-tcp-packet-duplication/64437 "2026-09-30T18:39:31Z")

</div>

Problem this snippet solves: This iApp provides full configuration of UDP/TCP packet duplication. It is commonly used to duplicate Syslog, SNMP Traps, Netflow, and Sflow data streams to multiple vendor solutions or cust…

---

## [Building iApps LX Extensions with AI](https://community.f5.com/t/building-iapps-lx-extensions-with-ai/77496)

<div class="topic-metadata">

**Author:** [@JRahm](https://community.f5.com/u/JRahm)\
**Replies:** 0\
**Last updated:** [September 30, 2026, 12:40pm UTC](https://community.f5.com/t/building-iapps-lx-extensions-with-ai/77496 "2026-09-30T12:40:23Z")

</div>

I’ve built a couple iApps LX extensions this year, on on versioning iRules and the other on performance optimization with iRules tracing capabilities. This guide is a summary of the iterative process in progressing from …

---

## [OOB Security Notification — Why you should patch NGINX Plus/Open Source now](https://community.f5.com/t/oob-security-notification-why-you-should-patch-nginx-plus-open-source-now/77005)

<div class="topic-metadata">

**Author:** [@WiliGasparetto](https://community.f5.com/u/WiliGasparetto)\
**Replies:** 1\
**Last updated:** [September 25, 2026, 9:52pm UTC](https://community.f5.com/t/oob-security-notification-why-you-should-patch-nginx-plus-open-source-now/77005 "2026-09-25T21:52:09Z")

</div>

On March 24, 2026, F5 published an out-of-band security notification covering multiple NGINX vulnerabilities affecting NGINX Plus (R32–R36) and NGINX Open Source (\<1.29.7 / \<1.28.3 in supported branches). While the advi…

---

## [F5 BIG-IP Advanced WAF Troubleshooting: What I Check First](https://community.f5.com/t/f5-big-ip-advanced-waf-troubleshooting-what-i-check-first/77368)

<div class="topic-metadata">

**Author:** [@WiliGasparetto](https://community.f5.com/u/WiliGasparetto)\
**Replies:** 1\
**Last updated:** [September 25, 2026, 9:48pm UTC](https://community.f5.com/t/f5-big-ip-advanced-waf-troubleshooting-what-i-check-first/77368 "2026-09-25T21:48:27Z")

</div>

When an application protected by F5 BIG-IP Advanced WAF / ASM starts failing, I try not to change the security policy immediately. Before disabling signatures, creating exceptions, or switching the policy to Transparent…

---

## [Restsh is now available under an Open Source license!](https://community.f5.com/t/restsh-is-now-available-under-an-open-source-license/76992)

<div class="topic-metadata">

**Author:** [@Juergen\_Mang](https://community.f5.com/u/Juergen_Mang)\
**Replies:** 11\
**Last updated:** [September 18, 2026, 8:43am UTC](https://community.f5.com/t/restsh-is-now-available-under-an-open-source-license/76992 "2026-09-18T08:43:51Z")

</div>

I am proud to announce that the complete Restsh package is now released under the GNU General Public License version 3 (GPLv3) or later. There are no hidden restrictions — we are not withholding any enterprise features. …

---

## [Automating BIG-IP Licensing Through iControl REST and the F5 Activation Service](https://community.f5.com/t/automating-big-ip-licensing-through-icontrol-rest-and-the-f5-activation-service/77414)

<div class="topic-metadata">

**Author:** [@VishnuG](https://community.f5.com/u/VishnuG)\
**Replies:** 0\
**Last updated:** [September 16, 2026, 6:16pm UTC](https://community.f5.com/t/automating-big-ip-licensing-through-icontrol-rest-and-the-f5-activation-service/77414 "2026-09-16T18:16:38Z")

</div>

Licensing a newly deployed BIG-IP normally requires interactive GUI steps or BIG-IQ. This Python utility automates direct licensing through BIG-IP iControl REST and the public F5 Activation Service without requiring BIG-…

---

## [Fixing GTM iQuery to use dtca/dtdi certs after the clientAuth EKU sunset](https://community.f5.com/t/fixing-gtm-iquery-to-use-dtca-dtdi-certs-after-the-clientauth-eku-sunset/77409)

<div class="topic-metadata">

**Author:** [@TimRiker](https://community.f5.com/u/TimRiker)\
**Replies:** 1\
**Last updated:** [September 15, 2026, 8:11pm UTC](https://community.f5.com/t/fixing-gtm-iquery-to-use-dtca-dtdi-certs-after-the-clientauth-eku-sunset/77409 "2026-09-15T20:11:57Z")

</div>

Every BIG-IP in a device trust domain already holds a device trust identity certificate — dtdi.crt, signed by the trust domain CA, dtca.crt. That is what device trust uses to authenticate one device to another. It is a p…

---

## [Need to Download a Ton of F5 XC Logs in CSV? Here's a Tool for That](https://community.f5.com/t/need-to-download-a-ton-of-f5-xc-logs-in-csv-heres-a-tool-for-that/77390)

<div class="topic-metadata">

**Author:** [@NormanMadeira](https://community.f5.com/u/NormanMadeira)\
**Replies:** 0\
**Last updated:** [September 14, 2026, 4:57am UTC](https://community.f5.com/t/need-to-download-a-ton-of-f5-xc-logs-in-csv-heres-a-tool-for-that/77390 "2026-09-14T04:57:55Z")

</div>

If you’ve worked with F5 Distributed Cloud (F5 XC) for any length of time, you’ve probably had to download logs during a troubleshooting or security investigation. And if you’ve ever needed more than 500 logs, you’ve pr…

---

## [Automatic NTP Auth Key Restoration after TMOS Upgrades](https://community.f5.com/t/automatic-ntp-auth-key-restoration-after-tmos-upgrades/77377)

<div class="topic-metadata">

**Author:** [@hauptem](https://community.f5.com/u/hauptem)\
**Replies:** 1\
**Last updated:** [September 7, 2026, 6:03am UTC](https://community.f5.com/t/automatic-ntp-auth-key-restoration-after-tmos-upgrades/77377 "2026-09-07T06:03:04Z")

</div>

Per F5’s knowledge base (K000139030), NTP keys do not survive a TMOS upgrade and must be reinstalled, with an ntpd restart, after every upgrade. For those of us where NTP authentication is a compliance requirement, this …

---

## [The State Of HTTP/2 Full Proxy With F5 LTM](https://community.f5.com/t/the-state-of-http-2-full-proxy-with-f5-ltm/76637)

<div class="topic-metadata">

**Author:** [@Juergen\_Mang](https://community.f5.com/u/Juergen_Mang)\
**Replies:** 15\
**Last updated:** [August 28, 2026, 6:10pm UTC](https://community.f5.com/t/the-state-of-http-2-full-proxy-with-f5-ltm/76637 "2026-08-28T18:10:31Z")

</div>

Code is community submitted, community supported, and recognized as ‘Use At Your Own Risk’. In this article, I will attempt to summarize the known challenges of an HTTP/2 full proxy setup, point out possible solutions, a…

---

## [NGINX Plus, NGINX OSS and NGINX Operator Correlations](https://community.f5.com/t/nginx-plus-nginx-oss-and-nginx-operator-correlations/77317)

<div class="topic-metadata">

**Author:** [@Darwin\_Tolbert](https://community.f5.com/u/Darwin_Tolbert)\
**Replies:** 0\
**Last updated:** [August 6, 2026, 11:41pm UTC](https://community.f5.com/t/nginx-plus-nginx-oss-and-nginx-operator-correlations/77317 "2026-08-06T23:41:18Z")

</div>

The NGINX Ingress Operator does not follow a strict lock-step minor version numbering scheme with the NGINX Plus Ingress Controller (NIC). Instead, compatibility is maintained through a specific mapping where newer opera…

---

## [Weblogic JSessionID Persistence](https://community.f5.com/t/weblogic-jsessionid-persistence/65133)

<div class="topic-metadata">

**Author:** [@unRuleY\_95363](https://community.f5.com/u/unRuleY_95363)\
**Replies:** 9\
**Last updated:** [August 3, 2026, 2:12pm UTC](https://community.f5.com/t/weblogic-jsessionid-persistence/65133 "2026-08-03T14:12:02Z")

</div>

Problem this snippet solves: Contributed by: unRuleY, Summarized by: deb Note: The previous version of this iRule contained escaped newlines following the session command, which in versions 10.0 - 10.2.0 causes TMM to …

---

## [Weblogic JSessionID Persistence for Session Replication](https://community.f5.com/t/weblogic-jsessionid-persistence-for-session-replication/67163)

<div class="topic-metadata">

**Author:** [@hoolio](https://community.f5.com/u/hoolio)\
**Replies:** 3\
**Last updated:** [August 3, 2026, 2:03pm UTC](https://community.f5.com/t/weblogic-jsessionid-persistence-for-session-replication/67163 "2026-08-03T14:03:56Z")

</div>

Problem this snippet solves: Persists HTTP requests on the primary and secondary server values found in the JSESSIONID cookie when the WebLogic servers implement session replication across two servers. The actual JSESSI…

---

## [F5 BIG-IP Multi-Site Dashboard](https://community.f5.com/t/f5-big-ip-multi-site-dashboard/76560)

<div class="topic-metadata">

**Author:** [@hauptem](https://community.f5.com/u/hauptem)\
**Replies:** 2\
**Last updated:** [July 23, 2026, 8:43pm UTC](https://community.f5.com/t/f5-big-ip-multi-site-dashboard/76560 "2026-07-23T20:43:27Z")

</div>

Code is community submitted, community supported, and recognized as ‘Use At Your Own Risk’. A comprehensive real-time monitoring dashboard for F5 BIG-IP Application Delivery Controllers featuring multi-site support, DNS …

---

## [F5OS using Ansible Linux Shell with remote users as iCall replacement(works with banner as well).](https://community.f5.com/t/f5os-using-ansible-linux-shell-with-remote-users-as-icall-replacement-works-with-banner-as-well/77213)

<div class="topic-metadata">

**Author:** [@Nikoolayy1](https://community.f5.com/u/Nikoolayy1)\
**Replies:** 1\
**Last updated:** [July 13, 2026, 9:24am UTC](https://community.f5.com/t/f5os-using-ansible-linux-shell-with-remote-users-as-icall-replacement-works-with-banner-as-well/77213 "2026-07-13T09:24:23Z")

</div>

(AI Made picture so don’t take it as 100% truth) In F5OS 1.8.0 and up remote users can automatically enter the Linux Shell if they have the correct remote group parameters and if this is system level enabled as sho…

---

## [A Method for the Madness: Meet HTTP QUERY](https://community.f5.com/t/a-method-for-the-madness-meet-http-query/77265)

<div class="topic-metadata">

**Author:** [@JRahm](https://community.f5.com/u/JRahm)\
**Replies:** 0\
**Last updated:** [July 10, 2026, 6:03pm UTC](https://community.f5.com/t/a-method-for-the-madness-meet-http-query/77265 "2026-07-10T18:03:56Z")

</div>

Note to the reader: I saw a headline on the new QUERY method and in a quick read didn’t really understand the need, so I did a deep dive with Claude to understand the method itself, then followed with the larger infrast…

---

## [Advanced WAF IP Exceptions Manager](https://community.f5.com/t/advanced-waf-ip-exceptions-manager/77226)

<div class="topic-metadata">

**Author:** [@amit-zakay](https://community.f5.com/u/amit-zakay)\
**Replies:** 0\
**Last updated:** [June 25, 2026, 1:14pm UTC](https://community.f5.com/t/advanced-waf-ip-exceptions-manager/77226 "2026-06-25T13:14:07Z")

</div>

I recently developed a dedicated Python-based tool for managing IP whitelist exceptions in F5 BIG-IP Advanced WAF policies. The goal was simple: make day-to-day exception management faster, cleaner, and less error-prone…

---

## [BIG-IP Report](https://community.f5.com/t/big-ip-report/67503)

<div class="topic-metadata">

**Author:** [@Patrik\_Jonsson](https://community.f5.com/u/Patrik_Jonsson)\
**Replies:** 102\
**Last updated:** [June 25, 2026, 4:34am UTC](https://community.f5.com/t/big-ip-report/67503 "2026-06-25T04:34:41Z")

</div>

Problem this snippet solves: Overview This is a script which will generate a report of the BIG-IP LTM configuration on all your load balancers making it easy to find information and get a comprehensive overview of virtu…

---

## [APM SAML IdP - SP Issuer Extraction](https://community.f5.com/t/apm-saml-idp-sp-issuer-extraction/65181)

<div class="topic-metadata">

**Author:** [@Nobby](https://community.f5.com/u/Nobby)\
**Replies:** 8\
**Last updated:** [June 24, 2026, 2:54pm UTC](https://community.f5.com/t/apm-saml-idp-sp-issuer-extraction/65181 "2026-06-24T14:54:02Z")

</div>

Problem this snippet solves: APM doesn’t expose any detail about the SAML SP Issuer when authentication requests hitting APM as an IdP during an SP initiated SAMLRequest. This iRule when applied to a SAML IdP enabled vi…

---

## [Creating a tmsh script with iControl REST and using it to restart HTTPD](https://community.f5.com/t/creating-a-tmsh-script-with-icontrol-rest-and-using-it-to-restart-httpd/68951)

<div class="topic-metadata">

**Author:** [@Mark\_Lloyd](https://community.f5.com/u/Mark_Lloyd)\
**Replies:** 3\
**Last updated:** [June 23, 2026, 6:04am UTC](https://community.f5.com/t/creating-a-tmsh-script-with-icontrol-rest-and-using-it-to-restart-httpd/68951 "2026-06-23T06:04:44Z")

</div>

Problem this snippet solves: TMSH has the ability to create tcl scripts that can be used to run multiple commands and transactions. It is rare that you will want to create on with TMSH but there are a few cases where th…

---

## [F5OS restarting container services through REST API](https://community.f5.com/t/f5os-restarting-container-services-through-rest-api/77204)

<div class="topic-metadata">

**Author:** [@Nikoolayy1](https://community.f5.com/u/Nikoolayy1)\
**Replies:** 2\
**Last updated:** [June 19, 2026, 6:31am UTC](https://community.f5.com/t/f5os-restarting-container-services-through-rest-api/77204 "2026-06-19T06:31:50Z")

</div>

(The Image is made with ChatGPT AI just to highlight the F5OS kubernetes cluster, for exact list of the kubernetes pods see myF5) Most of the F5OS services are in docker containers as F5OS is made of kubernetes clu…

---

## [Intent-Based Load Balancing for AI Traffic on BIG-IP](https://community.f5.com/t/intent-based-load-balancing-for-ai-traffic-on-big-ip/77194)

<div class="topic-metadata">

**Author:** [@Keling\_JI](https://community.f5.com/u/Keling_JI)\
**Replies:** 0\
**Last updated:** [June 13, 2026, 2:07pm UTC](https://community.f5.com/t/intent-based-load-balancing-for-ai-traffic-on-big-ip/77194 "2026-06-13T14:07:52Z")

</div>

AI applications often start with a simple pattern: one client, one API endpoint, one model. That works for a demo, but it becomes limiting quickly. In real environments, different requests may need different treatment. …

---

## [HTTP/2 bomb attack - is BIG-IP vulnerable against CVE-2026-49975?](https://community.f5.com/t/http-2-bomb-attack-is-big-ip-vulnerable-against-cve-2026-49975/77178)

<div class="topic-metadata">

**Author:** [@Daniel\_Wolf](https://community.f5.com/u/Daniel_Wolf)\
**Replies:** 0\
**Last updated:** [June 10, 2026, 5:38am UTC](https://community.f5.com/t/http-2-bomb-attack-is-big-ip-vulnerable-against-cve-2026-49975/77178 "2026-06-10T05:38:10Z")

</div>

tl;dr The answer is: No Intro Two days earlier (June 2) Calif, a security firm from California, published a blog post about a new HTTP/2 DoS attack, that chains two attack techniques: a compression bomb and a Slowloris-…

---

## [Enhancing the F5 DoD Banner with EU CAPTCHA (Myra) & Sideband Validation](https://community.f5.com/t/enhancing-the-f5-dod-banner-with-eu-captcha-myra-sideband-validation/77176)

<div class="topic-metadata">

**Author:** [@fredlubrano](https://community.f5.com/u/fredlubrano)\
**Replies:** 0\
**Last updated:** [June 8, 2026, 7:06am UTC](https://community.f5.com/t/enhancing-the-f5-dod-banner-with-eu-captcha-myra-sideband-validation/77176 "2026-06-08T07:06:18Z")

</div>

Features & Security Hardening (v1.3) Besides the frontend EU CAPTCHA integration, this iRule introduces several security hardening measures (P3–P9): Strict POST Enforcement: Banner acceptance is strictly limited to POS…

---

## [Automating TLS Certificates in Kubernetes with cert-manager and F5 Distributed Cloud DNS](https://community.f5.com/t/automating-tls-certificates-in-kubernetes-with-cert-manager-and-f5-distributed-cloud-dns/77138)

<div class="topic-metadata">

**Author:** [@mkylian](https://community.f5.com/u/mkylian)\
**Replies:** 1\
**Last updated:** [May 29, 2026, 10:25am UTC](https://community.f5.com/t/automating-tls-certificates-in-kubernetes-with-cert-manager-and-f5-distributed-cloud-dns/77138 "2026-05-29T10:25:51Z")

</div>

Introduction If you run workloads in Kubernetes or Open Shift, you’ve almost certainly dealt with TLS certificates. You need them everywhere — Ingress controllers, internal services, mutual TLS between microservices, and…

---

## [F5 certificate deployment with iControl REST and HashiCorp Vault](https://community.f5.com/t/f5-certificate-deployment-with-icontrol-rest-and-hashicorp-vault/77114)

<div class="topic-metadata">

**Author:** [@Juergen\_Mang](https://community.f5.com/u/Juergen_Mang)\
**Replies:** 0\
**Last updated:** [May 14, 2026, 4:13pm UTC](https://community.f5.com/t/f5-certificate-deployment-with-icontrol-rest-and-hashicorp-vault/77114 "2026-05-14T16:13:13Z")

</div>

Welcome to the first article in a comprehensive series dedicated to administrating F5 BIG-IP systems through the power of the iControl REST API. This series is designed for both beginners and experienced network administ…

---

## [The Blind Spot in Cloud WAF Architectures: Shared IPs and the Origin Bypass Problem](https://community.f5.com/t/the-blind-spot-in-cloud-waf-architectures-shared-ips-and-the-origin-bypass-problem/77104)

<div class="topic-metadata">

**Author:** [@Injeyan\_Kostas](https://community.f5.com/u/Injeyan_Kostas)\
**Replies:** 1\
**Last updated:** [May 11, 2026, 5:49am UTC](https://community.f5.com/t/the-blind-spot-in-cloud-waf-architectures-shared-ips-and-the-origin-bypass-problem/77104 "2026-05-11T05:49:53Z")

</div>

Cloud WAFs are a widely adopted security control, but they carry a structural trust assumption that most operators never examine: whitelisting a vendor’s IP ranges grants access not just to your WAF instance, but to ever…

---

## [Radware config translation](https://community.f5.com/t/radware-config-translation/67473)

<div class="topic-metadata">

**Author:** [@PeteWhite](https://community.f5.com/u/PeteWhite)\
**Replies:** 31\
**Last updated:** [April 27, 2026, 1:21pm UTC](https://community.f5.com/t/radware-config-translation/67473 "2026-04-27T13:21:27Z")

</div>

Problem this snippet solves: This is a simple Python script that translates Radware text configuration file and outputs as config snippet and certificate files. $ ./rad2f5 Usage: rad2f5 \<filename\> \[partition\] Example: …

---

## [Complete MFA solution with GA stored in Active Directory](https://community.f5.com/t/complete-mfa-solution-with-ga-stored-in-active-directory/68860)

<div class="topic-metadata">

**Author:** [@Vladimir\_Akhmarov](https://community.f5.com/u/Vladimir_Akhmarov)\
**Replies:** 9\
**Last updated:** [April 14, 2026, 5:03pm UTC](https://community.f5.com/t/complete-mfa-solution-with-ga-stored-in-active-directory/68860 "2026-04-14T17:03:37Z")

</div>

Problem this snippet solves: All modern business applications require Multi-Factor Authentication (MFA) to be used for remote access by employees. There are many vendors on market selling enterprise MFA solutions that m…

[Next page](https://community.f5.com/c/articles/codeshare/15.md?page=1)
