Forum Discussion
Block an IP when Session Transactions Anomaly Detected
I'm attempting to block an IP automatically when the 'Session Transactions Anomaly' is detected. The default response behavior is to block the offending session from making any additional requests. The scraper has 20 threads running, when one thread violates the policy (which takes a few minutes) he opens a new thread and starts again. Keep in mind, this is not a 'Session Opening' violation where we can implement 'Persistant Client Identification' to track IP.
I was pointed to this iRule but it is producing inconsistent results.
Ideally, the policy tracks the IP for a certain number of requests, when a threshold is reached it is blocked the IP from making additional requests for a specified period of time.
1 Reply
- R_Eastman_13667Historic F5 Account
This should help you: https://devcentral.f5.com/wiki/iRules.AccessControlBasedOnNetworkOrHost.ashx
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com