Forum Discussion
mpfeifer_63884
Nimbostratus
Feb 09, 2010How to handle ASM in HTTP_CLASSes
Hi.
We're having some issues setting up our ASM, as it behaves quite strangely.
First, I'll try to explain our setup:
We have various VirtualServers (VS) and we use HTTP_CLASS-Profiles a lot to redirect our traffic.
Now we'd like to activate ASM and we do the following: we create a HTTP_CLASS and enable ASM in it. This HTTP_CLASS does nothing more.
Then we add this HTTP_CLASS-Profile as resource in a VS, and it seems to work. Although, if we put this Profile as the first in the list, the other HTTP_CLASS-Profiles do not work anymore. Given this strange behaviour, we think, maybe this is not the real way to enable/implement ASM on the LTM?
Could you give us some advise?
Thank you.
Markus
3 Replies
- hoolio
Cirrostratus
Hi Markus,
Only one HTTP class can be matched and used to process a single HTTP request.
If you have some requests you want to redirect, you could add the ASM enabled HTTP class last in the list of classes on the VIP. All requests which were previously redirected using the non-ASM HTTP classes would still be redirected (without going through ASM). All other requests which don't match a non-ASM redirecting class would be sent to ASM and then the pool on the ASM HTTP class. If the ASM HTTP class doesn't have a pool configured then the VIP's default pool would be used.
Aaron - mpfeifer_63884
Nimbostratus
Hi Aaron.
Thanks for your reply.
Although it doesn't quite reflect our problem.
By saying that we use HTTP-class to "redirect our traffic" I mean something like "if URI is foo, then use pool bar"
But we still would like to have this action protected by the ASM-Module.
As I understand, putting the ASM-enabled HTTP-class at the end of the VIP resources list, would not protect the actions done by the previous HTTP-classes.
I hope I could explain the issue.
regards,
Markus - hoolio
Cirrostratus
Hi Markus,
Thanks for clarifying. If you want to do pool selection and use ASM validate the traffic, you can enable ASM on each HTTP class. This would require separate ASM web apps for each class. If you want to use one policy for all of the web apps, you'd need to manually export and import the policy between web apps. This would be a nuisance from a management perspective.
Another option would be to use a single HTTP class with ASM enabled and no filters. All traffic would match this class. You could then use an iRule to do the pool selection. You can do pool selection in the HTTP_CLASSS_SELECTED event.
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects