Forum Discussion
Hits from one IP address taking our site down
We are using Big IP ASM version 11.3, and have blocked all geolocations outside of the United States and Canada (we do business only within the US). This past weekend we had enough hard hits from an IP address in Germany, that our site was unavailable for a bit. This was immediately before and immediately after midnight Saturday. We stopped and restarted TomCat, and the issue was resolved. My question is this: Is there something more that we could or should be doing to prevent this type of attack? We are not using DoS, nor web scrapping because even at the lowest settings, we were actually blocking some of our punch-out customers from our eCommcerce site. I welcome any ideas and thoughts about this. Many thanks ~ Dianna
13 Replies
- Dianna_129659
Nimbostratus
Thank you all for your ideas and suggestions. Yes, we block using ASM GeoLocation Enforcement. The logs do not indicate that the user was able to access our site. I suppose it might have simply been an overload to our server at the same time that the one IP Address was hitting several times each second. We have actually had that same type of hit in the past, but it never took the site down. Unless it happens again, I will chalk this up to coincidence of attack and server overload. I appreciate this forum very much. Thank you!
- Torti
Cirrus
if it is the Geolocation Enforcement, this is a good artical about it: Geolocation Enforcement
- Ido_Breger_3805Historic F5 Account
I assume Diana is using the built in GUI feature within ASM ("Geolocation Enforcement")
- Torti
Cirrus
ah ok, I did find it.
- Torti
Cirrus
How do you block all other contries? Do you use the IP Address Intelligence or an irule?
- Ido_Breger_3805Historic F5 Account
Hi Diana, If the ASM is configured to block all source IPs coming outside the US and you managed to see a request with a source IP from Germany then it sounds like a miss-configuration to me. I suggest you open a support case so we can look at your configuration. Kind Regards, Ido
- Torti
Cirrus
So, if requests from outside the US will be blocked, it is really strange and see only 3 reasons.
- attacks from US server at the same time
- overload of the bigip so that every traffic was blocked
- an unfortunate accident of an attack and a problem with the tomcat at the same time
regards
- Torti_93733
Nimbostratus
how can your tomcat crash by requests with an IP outside the US, if you block all traffic from ouside the US? It should be blocked by the ASM.
Comment: Are you sure, that all your business partner use server in the US?
greetings from germany ;-)
- you say: "Yes, they were blocked, but our site actually went down at that time, so it seems that the the attack caused the site to go down." i would focus on that, is there any logging on the tomcat that shows which IPs reached it?
- Dianna_129659
Nimbostratus
Hi Torti. Thank you for your greeting from Germany. Yes, all of our trading partners are located in and use servers in the US. We are unable to ship huge products outside of US. I ask the same question you did - how could this happen when we are blocking? I wondered if I was missing something. When I look at the HTTP Request details, it appears that the user was trying to inject script into forms on out site. Yes, they were blocked, but our site actually went down at that time, so it seems that the the attack caused the site to go down. So, we stopped and restarted TomCat, and the problem was resolved. Maybe there is no connection, but it seems quite possible.
- Torti
Cirrus
how can your tomcat crash by requests with an IP outside the US, if you block all traffic from ouside the US? It should be blocked by the ASM.
Comment: Are you sure, that all your business partner use server in the US?
greetings from germany ;-)
- you say: "Yes, they were blocked, but our site actually went down at that time, so it seems that the the attack caused the site to go down." i would focus on that, is there any logging on the tomcat that shows which IPs reached it?
- Dianna_129659
Nimbostratus
Hi Torti. Thank you for your greeting from Germany. Yes, all of our trading partners are located in and use servers in the US. We are unable to ship huge products outside of US. I ask the same question you did - how could this happen when we are blocking? I wondered if I was missing something. When I look at the HTTP Request details, it appears that the user was trying to inject script into forms on out site. Yes, they were blocked, but our site actually went down at that time, so it seems that the the attack caused the site to go down. So, we stopped and restarted TomCat, and the problem was resolved. Maybe there is no connection, but it seems quite possible.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com