Forum Discussion
DoS Profile (ASM) - Rate limiting implementation
ASM has a DoS profile with TPS-based detection, by Device IP. Offenders can be rate limited.
How does this rate limiting apply? Is it layer 4 or layer 7? If TCP, does it drop TCP packets (no ACK) or does it drop the TCP connection?
This is not described in the documentation and different implementations would have very different impact for legitimate users who are flagged as offenders (false positives).
- samstepCirrocumulus
It depends on how you configure it. If you are worried about false positives ASM can issue a CAPTCHA challenge to suspicious IP addresses instead of blocking, it can also shows the blocking page or just block the IP address.
Documentation can be found here:
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com