Forum Discussion
funkdaddy_31014
Aug 13, 2012Nimbostratus
Block an external IP from ALL Virtual Servers?
Occasionally our intrusion detection software will detect nefarious IP addresses from which we would like to block access to all Virtual servers on the Big-IP.
Is there a way to do this on on an LTM (3900, v10) for the external interface (or all interfaces) without using an iRule?
3 Replies
Sort By
- is packet filter applicable?
- funkdaddy_31014NimbostratusThanks - is there (CPU/Load) overhead to enabling packet filtering?
- hoolioCirrostratusThere is a performance hit for using packet filters, but like iRules, it's dependent on the profile of the traffic and the complexity of the iRules. You could test this in a lab environment to get an idea of the resource utilization for your specific scenario.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects