Forum Discussion
Can F5 be in Bridge Mode or a L2 DDOS to protect from L3-L4 DDOS attack
Hi F5 community,
We just want to consult if F5 rSeries models ( Active-Standby HA setup ) with AFM license is capable to do bridge mode to cater L3-L4 DDOS protection before it goes to Internet Perimeter FW.
We ask this so that there will be no re-architecture or change of config about the Public IP defined in the Internet Perimeter FW.
If you have any document experience or KB article pertaining to this it will be a great help to us. Thank you in advance.
T0nyP This seems like what you are looking for but not 100%.
T0nyP This seems like what you are looking for but not 100%.
You mean vlangroup or vwire ? rSeries with the latest 1.3.x software now supports vwire https://clouddocs.f5.com/f5os/F5OS-A/v1.3.0/F5OS-A-1.3.0-virtual-wire-support-cBIP-15.1.8.html and I have done AFM DOS on vwire (not on rSeries but the same should be true).
As you may not have self-ip things like tcp cookies (afm AFM TCP Half Open vector) may not work in vWire but dropping tcp sync fload attack will work, so there are some small limitations to keep in mind.
- T0nyPCirrus
Highly appreciate your guidance and thanks much for informing me about vWire feature for L2 DDOS Setup.
Additonal inquiry only.
Do we still need to setup a FW policy? And in what context do you recommend to apply the FW policy?
Thanks in advance.
I can't tell you if you need AFM policy as this is something that you need to be aware of as admin of the network environment if you need not only DOS protection but also security rules.
The AFM policy is usually global for such deployments but if you do not have good knowedge in AFM and rSeries better involve F5 PS as you are risking to much as the Devcentral community that F5 professionals are helping each other for some basic or complex questions can't replace training or a PS consultant.
T0nyP - noticed this sorta old conversation that looks like it was resolved? If so...it would be great if you could choose Accept As Solution on as many replies as you considered helpful.
Thanks for being part of our community.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com