Forum Discussion
BIG-IP AFM DoS Device Protection source IPs logged?
Are the source IPs of a DoS attack logged on the F5 anywhere?
- hosting-teamNimbostratusVector: TCP bad ACK flood
Trigger: Volumetric, Aggregated across all SrcIP's, Device-Wide attack, metric:PPS
Mitigation: Blocked
We see this but would the source IPs have been logged?
The KB shows IPs in a packtet capture during a DoS but I assume that is not turned on by default. - AubreyKingF5Moderator
Logging on a DoS firewall needs to be carefully dialed in. If we were to turn on source logging by default, a 3DoS could fill a BIG-IP disk in minutes, or even seconds, depending on the attack. Unfortunately, the answer to your question is 'No,' however.. I would highly encourage you to get a dedicated physical link on your F5 - as big as you can get it.. maybe 2 ports per box, aggregated - for logging, if you want to do DoS logging. Then, you need to set up a logging profile:
https://support.f5.com/csp/article/K51266926That should be enough to point you in the right direction.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com