Forum Discussion

Sundar_92896's avatar
Sundar_92896
Icon for Nimbostratus rankNimbostratus
Sep 29, 2009

Block traffic to VIP/LTM/GTM on the basis of origin

Is it possible to block traffic on the basis of origin like traffic from certain countries, i am interested to block/redirect traffic originating from certain countries..

 

 

I believe this is possible with 10.0 ver, i would really appreciate if anyone can help me on this..

 

  • James_Quinby_46's avatar
    James_Quinby_46
    Historic F5 Account
    You can define topologies based on country of origin, though this is only going to be as good as the GeoIP database, and could be circumvented by the use of a proxy.

     

     

    There is information on topologies in the admin guide. Click here
  • hoolio's avatar
    hoolio
    Icon for Cirrostratus rankCirrostratus
    And wouldn't someone still be able to access the VIP by IP address (or another non-DNS method for resolving the FQDN to the virtual server IP address)?

     

     

    I could be wrong, but I don't think there is a simple solution for doing this effectively on LTM as LTM doesn't have the ability to reference the GTM GeoIP database from an iRule. That might make a good feature request.

     

     

    Aaron