Forum Discussion
ASM - pool to be defined in http class or in VIP ?
We are having two LTMs running ASM. There are two virtual servers created one for 'http' and one for 'https' (for SSL offload).
1. When we are enabling ASM, do we need to define the default pool in the 'https' virtual server or we do we need to define the pool ONLY in the 'http class' ?
2. If we define default pool in the in the 'https' virtual server as well as in the 'http class' is there any security risk ?
I would appreciate if you could share your expert opinion on this.
Rgds./
Joe.
- hoolio
Cirrostratus
Hi Joe, - member123_60341
Nimbostratus
Thanks Aaron for you your quick response. - hoolio
Cirrostratus
If you're redirecting HTTP to HTTPS you can use a simple iRule or an HTTP class without ASM enabled. The action on the class would be redirect to https://[HTTP::host][HTTP::uri]. You would not want or need to add a pool to this VIP or class as it would never be used. - member123_60341
Nimbostratus
Hi Aaron, - hoolio
Cirrostratus
The way you have it configured is secure and fine. - member123_60341
Nimbostratus
Hi Aaron, - hoolio
Cirrostratus
Hi Joe, - Wallace1
Nimbostratus
Hi Aaron,
I have a VIP with several HTTPClasses. Do I need to add ASM to each HTTPclass? or is there a way to call ASM via an irule?
Thanks
Wallace
- nathe
Cirrocumulus
Wallace,
"Do I need to add ASM to each HTTPclass?" - depends really. The Http class profiles can distinguish the traffic based on Host name, URI etc and then enable ASM or not. They work in a top down order too and the first one it matches it uses. If you want all the traffic to be security enabled, notwithstanding the order config in the class then yes, you may have to enable it on every one.
Re irules and ASM see: https://devcentral.f5.com/wiki/iRules.asm.ashx
Hope this helps, N
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com