Forum Discussion
F5 XC WAF Automation for Bulk IP Prefix Blocking
I've a requirement to block more than 5,000 IP addresses in F5 Distributed Cloud (XC) WAF.
Is there any supported option to automate the creation or update of IP Prefix Sets using scripts or APIs, instead of adding the prefixes manually through the UI?
The goal is to automate the process of importing and maintaining the IP prefixes used for blocking traffic.
Thank you.
2 Replies
You can use service policy with prefix sets or prefix lists.
Each prefix set can have up 1024 ip addresses but you can attach many prefix sets in service policy rule.
How to create IP Prefix Sets with API Calls (cURL and Postman)
Still you need your automation to also remove old entries after time as to not consume everything over time and using IP reputation/IP intelligence that is free in XC may provide better detection for bad IP addresses to be honest.
Configure IP Reputation Service | F5 Distributed Cloud Technical Knowledge
Also XC Malicious User detection can add extra blocking for bad ip addresses for some preconfigured time.
Enable Malicious User Detection and Mitigation | F5 Distributed Cloud Technical Knowledge
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com