Forum Discussion
Botnet Mitigation if traffic initiated from inside to outside
Hi Deepak,
With what modules ? If a Botnet appeared on your internal Network, that's slightly worrying and hopefully would be picked up by a security function within your business.
If your specifically concerned about a certain application subnet, how does it currently access the internet ? Does it need to access the internet? If its just for an application, can you restrict the IP's it gets to, websites etc etc. (You're bordering on WebProxy territory here)
Could you deploy ASM and look at the application traffic, learn what is "Normal" and log/drop things that aren't ?
From the information you've provided, its very difficult to answer the question. But hopefully the above will help direct you down the right path.
We would configure forwarding virtual server from inside to outside.
SourceProxyIP--> Destination any any--> SNAT to VIP
In this scenario u mean let the proxy do the botnet protection . Then F5 will by pass the traffic only to the internet.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com