Forum Discussion
ASM DoS Protection and Trust-XFF-Header
Does anyone know if the ASM DoS Protection will respect the IP Address defined the the ASM Policy Configuration (Advanced), where you can enable "Trust XFF Header" which specifies the HTTP Header to use that contains the IP of the end client?
e.g. If there is traffic coming in from many end clients through a trusted proxy which inserts the end user IP Address into a HTTP Header, then if we define the ASM Policy to use this header, and then define a DoS Protection Profile set to use Source IP-Based Rate limiting, then will this rate limit apply to the connections from the proxy or from each end user?
1 Reply
- Erik_Novak
Employee
You should be able to do this by enabling "Accept XFF" on the HTTP profile (Local Traffic>Profiles>Services>HTTP> Properties. This ensures the DoS profile will trust the XFF you specify, rather than the security policy. This method started with v11.5.1.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com