Forum Discussion
ASM Prevention for Slow HTTP Attacks
Hi Team, I have been reading the article https://support.f5.com/kb/en-us/solutions/public/14000/100/sol14199 after starting to notice these logs files on my F5. Now from the article these are slow HTTP connections being dropped but what I really want to know is:
- What is the threshold for these slow transactions dropping ?
- And can I find out any information on these dropped transactions ? If these are slow attacks, source IP and destination IP would be handy.
It all seems a bit "under the covers" in regards to what is happening here and I would love to find more information
err dcc[13309]: 01310001:3: event code D3554 Slow transactions attack detected - account id: (9), number of dropped slow transactions: (128)
err dcc[13309]: 01310001:3: event code D3554 Slow transactions attack detected - account id: (9), number of dropped slow transactions: (2428)
1 Reply
- nathe
Cirrocumulus
It's an Internal Parameter. Check out:
The parameters of interest are Max_slow_transactions and slow_transactions_timeout.
N
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com