Forum Discussion
Brute force protection for an API endpoint (no login page)?
Hello Mohamed.
Actually, you have a default "Brute Force Attack Prevention" profile which applies to all the URLs not manually defined.
"You can add default brute force protection when creating a security policy using the Deployment wizard. If you do, the policy simply needs to know for which login pages to enforce brute force protection. The system creates a default brute force configuration that applies to all defined login URLs that are not associated with any other brute force configuration."
See this path ->
Security > Application Security > Anomaly Detection > Brute Force Attack Prevention
KR,
Dario.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com