DoS attack - how do I know?
Sorry for this somewhat general question - we're just trying to understand how various Denial of Service attacks can be identified on the Big-IP. Are there particular log messages we would expect to see when under attack? Are there any recommendations on monitoring for DoS attacks? Also, when under attack, what recommended actions can be done in real time? For instance, is it reasonable and feasible to identify and block particular IP addresses on the VIP level?
I am aware of some of the LTM's features to mitigate DoS attacks as outlined in the Implementations guide. Any other resources, kb articles, etc would be greatly appreciated.