Forum Discussion
Can I use F5 Big-IP WAF as HoneyPot
Hi RockBD,
the answer is - it depends.
You cannot create a high interaction honeypot with ASM or with iRules.
With iRules you could do something like - if URL is /admin-login respond with a dummy form page.
Or an iRule that just responds 200 OK to everything and logs all requests.
In general, I see a honeypot more as something you would do with iRules rather then with ASM or LTM.
With ASM you could use anomaly detection to redirect suspicious traffic to a honeypot server.
Or, with the help of iRules, based on violations, you could redirect clients to a honeypot server.
Or, again with iRules, you could setup fake URLs and redirect them to a honeypot server.
This github list a lot of honeypot systems: https://github.com/paralax/awesome-honeypots
Cheers
Daniel
- Nikoolayy1Jun 17, 2025
MVP
I agree with this answer. Also see https://my.f5.com/manage/s/article/K42323285 and https://my.f5.com/manage/s/article/K18650749 but F5 even when sending a page that looks like real server response is not meant to be full honeypod.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com