Forum Discussion

T0nyP's avatar
T0nyP
Icon for Cirrus rankCirrus
Apr 04, 2023

Can F5 be in Bridge Mode or a L2 DDOS to protect from L3-L4 DDOS attack

Hi F5 community,

We just want to consult if F5 rSeries models ( Active-Standby HA setup ) with AFM license is capable to do bridge mode to cater L3-L4 DDOS protection before it goes to Internet Perimeter FW.

We ask this so that there will be no re-architecture or change of config about the Public IP defined in the Internet Perimeter FW.

If you have any document experience or KB article pertaining to this it will be a great help to us. Thank you in advance.

  • T0nyP - noticed this sorta old conversation that looks like it was resolved? If so...it would be great if you could choose Accept As Solution on as many replies as you considered helpful.

    Thanks for being part of our community.

  • You mean vlangroup or vwire ? rSeries with the latest 1.3.x software now supports vwire https://clouddocs.f5.com/f5os/F5OS-A/v1.3.0/F5OS-A-1.3.0-virtual-wire-support-cBIP-15.1.8.html and I have done AFM DOS on vwire (not on rSeries but the same should be true).

     

    As you may not have self-ip things like tcp cookies (afm AFM TCP Half Open vector) may not work in vWire but dropping tcp sync fload attack will work, so there are some small limitations to keep in mind.

    • T0nyP's avatar
      T0nyP
      Icon for Cirrus rankCirrus

      Highly appreciate your guidance and thanks much for informing me about vWire feature for L2 DDOS Setup.

      Additonal inquiry only.

      Do we still need to setup a FW policy? And in what context do you recommend to apply the FW policy?

      Thanks in advance.

      • I can't tell you if you need AFM policy as this is something that you need to be aware of as admin of the network environment if you need not only DOS protection but also security rules.

         

        The AFM policy is usually global for such deployments but if you do not have good knowedge in AFM  and rSeries better involve F5 PS as you are risking to much as the Devcentral community that F5 professionals are helping each other for some basic or complex questions can't replace training or a PS consultant.