F5 is upgrading its customer support chat feature on My.F5.com. Chat support will be unavailable from 6am-10am PST on 1/20/26. Refer to K000159584 for details.

Forum Discussion

F5_Fan_162146's avatar
F5_Fan_162146
Icon for Nimbostratus rankNimbostratus
Oct 31, 2014

Block an IP when Session Transactions Anomaly Detected

I'm attempting to block an IP automatically when the 'Session Transactions Anomaly' is detected. The default response behavior is to block the offending session from making any additional requests. The scraper has 20 threads running, when one thread violates the policy (which takes a few minutes) he opens a new thread and starts again. Keep in mind, this is not a 'Session Opening' violation where we can implement 'Persistant Client Identification' to track IP.

 

I was pointed to this iRule but it is producing inconsistent results.

 

Ideally, the policy tracks the IP for a certain number of requests, when a threshold is reached it is blocked the IP from making additional requests for a specified period of time.