Forum Discussion
ASM policy block mode for one particular source IP address and remaining IPs ASM should be in transparent.
for traffic routing it is much better and easier to use the local traffic policy instead of an iRule.
If you need different blocking behaviour for just 1 IP address you are doing it wrong - maintaining 2 identical policies is a massive overhead - use Trusted IP address feature instead: https://support.f5.com/kb/en-us/products/big-ip_asm/manuals/product/asm-implementations-12-0-0/24.htmlunique_418795504
For remote logging simply configure the remote logging profile in your policy, here's the ASM manual chapter describing how to do this:
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com