Forum Discussion
Blocking access to ASM Vservers with IP in the host header.
Hi I am new to ASM and come from a Citrix WAF background, I am trying to find out the best way to block traffic going to the ASM with an IP in host entry. I know you can use an irule to drop the traffic but is this the most effective way or is there something inbuilt which would use less resource?
- youssef1
Cumulonimbus
Hello,
Just for blocking an IP in effective way, you can use packet filter.
Packet filters enhance network security by specifying whether a BIG-IP system interface should accept or reject certain packets based on criteria that you specify. Packet filters enforce an access policy on incoming traffic. They apply to incoming traffic only.
You can find more information here: https://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/tmos-implementations-12-1-0/26.html
https://devcentral.f5.com/wiki/AdvDesignConfig.PacketFiltering.ashx
Regards
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com