Apr 04, 2023

Can F5 be in Bridge Mode or a L2 DDOS to protect from L3-L4 DDOS attack

Hi F5 community,

We just want to consult if F5 rSeries models ( Active-Standby HA setup ) with AFM license is capable to do bridge mode to cater L3-L4 DDOS protection before it goes to Internet Perimeter FW.

We ask this so that there will be no re-architecture or change of config about the Public IP defined in the Internet Perimeter FW.

If you have any document experience or KB article pertaining to this it will be a great help to us. Thank you in advance.

  • You mean vlangroup or vwire ? rSeries with the latest 1.3.x software now supports vwire and I have done AFM DOS on vwire (not on rSeries but the same should be true).


    As you may not have self-ip things like tcp cookies (afm AFM TCP Half Open vector) may not work in vWire but dropping tcp sync fload attack will work, so there are some small limitations to keep in mind.

      Highly appreciate your guidance and thanks much for informing me about vWire feature for L2 DDOS Setup.

      Additonal inquiry only.

      Do we still need to setup a FW policy? And in what context do you recommend to apply the FW policy?

      Thanks in advance.

      • I can't tell you if you need AFM policy as this is something that you need to be aware of as admin of the network environment if you need not only DOS protection but also security rules.


        The AFM policy is usually global for such deployments but if you do not have good knowedge in AFM  and rSeries better involve F5 PS as you are risking to much as the Devcentral community that F5 professionals are helping each other for some basic or complex questions can't replace training or a PS consultant.

