Forum Discussion
Piotr_Lewandows
Apr 13, 2015Altostratus
Blocking icmp to VS using AFM
Hi,
I tried to use AFM to block icmp traffic to VS (or rather VIP). Seems to be not working, so is that by design or I am doing something wrong (I tested blocking http to http vs and it's workin...
- Apr 13, 2015
Try creating a global context rule that drops ICMP destined for the virtual address. This should work.
~Steve
Steve_Brown_882
Apr 13, 2015Historic F5 Account
Try creating a global context rule that drops ICMP destined for the virtual address. This should work.
~Steve
- dragonflymrApr 13, 2015CirrostratusHi, Well, it's working! I just wonder why VS context rule is not working but global is working? I guess I figured it out but if you can confirm: So ping is actually handled by VIP not VS so it's answered before traffic hits VS where VS context rule for rejecting ping is implemented - am I close? Piotr
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects