F5 is upgrading its customer support chat feature on My.F5.com. Chat support will be unavailable from 6am-10am PST on 1/20/26. Refer to K000159584 for details.

Forum Discussion

Raymond_Feng_97's avatar
Raymond_Feng_97
Historic F5 Account
May 07, 2013

Can we reject DNS request with IP header identification = "0x0000" ?

 

Hi, all

 

I am on POC testing for China Telecom LDNS enhancement cases. By now , customer found mostly DNS DDoS attack come with IP header identification = "0x0000" as attach JPG shows .

 

Sorry , I can't find any iRule function to check IP header identification value , can we use iRule to detect these packets ?

 

 

Best Rgds,

 

Raymond

 

 

No RepliesBe the first to reply