Forum Discussion
[AFM] Log implicite drop rule
Hi,
I have modified the global-network log profile to activate local log (by selecting local-ddb -publisher), the profile is associated with all VS but the implicite drop rule for all the context is not logged.
Is-it possible to log all drop rule ?
Thank you,
Best regards
5 Replies
- Thomas_Gobet
Nimbostratus
Hi,
You can't modify the implicite rule.
You have to define a "default" global rule with the log statement activated.
The result will be the same than what you wanted.
- brahim94_11525
Nimbostratus
So I have to define a default drop rule for every VS, SelfIP... ?
- Thomas_Gobet
Nimbostratus
Yes, for every VS.
If your trafic is under global level, you just need one global rule.
- Steve_Brown_882Historic F5 Account
You can change the log settings on the default action without creating an explicit rule. There is a DB key that can be changed in TMSH for the Global/Route-Domain context along with one for the Virtual Server/SelfIP context. I would be sure that the log server can keep up prior to changing these keys but other than that you should be ok.
Global Context - tmsh modify sys db tm.fw.globaldefaultrule.log value enable VS Context - tmsh modify sys db tm.fw.defaultrule.log value enable
- brahim94_11525
Nimbostratus
Hi Steve,
Thanks a lot for the feedback,
Best regards,
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com