Forum Discussion
F5 AFM IP intelligence whitelist content
I do not believe it is possible to extract a full dump of the IP addresses currently contained within an IP Intelligence category; you can only check if a single IP address is in a category with the following command:
show security ip-intelligence info address <IP ADDRESS>
Hi Michael, thanks for the reply we were facing an issue where an external IP is blacklisted as windows_exploit category so we created a custom category in the IP intelligence policy windows_exploit_bypass with action allow however while doing so the IP got recognized by both categories and still dropped.
When finally requesting BRighcloud to whitelist this IP address they performed it and is now allowed. This IP however is not really trusted as behind these IP exist a guest network where attacker launch attacks frequently.
So we should be able to bypass this locally as this is not a good security remediation. Other customers can now also be exposed to threats.
The category whitelist embedded on the F5 system cant be used in IPI policy, what would you recommend to do in this situation?
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com