Forum Discussion
I need an irule to rate limit new ssl sessions
My customer has a problem with one weblogic app that dont support massive connections in a short period. We need to control the rate that new SSL sessions are accepted
I have found irules samples to limit rate of new tcp sessions but I need to cntrol at ssl session level.
Any idea please?
4 Replies
- IheartF5_45022
Nacreous
When you say connections, do you mean HTTPS connections (are you doing serverside SSL?), HTTP requests or TCP connections?
- Irene_Garcia-An
Nimbostratus
I need to control the number of new users entering the app. I have tried controlling tcp sessions per second but the same user opens many tcp sessions in the same ssl session (ssl id) so I need to control at ssl session (ssl id) instead of tcp session.
We are not doing serverside SSL
- IheartF5_45022
Nacreous
Assuming you are using Hoolios rule https://devcentral.f5.com/wiki/iRules.virtual_server_connection_rate_limit_with_tables.ashx , I think you'll need to move the table additions/checks to CLIENTSSL_HANDSHAKE, and use the key "[IP::client_addr]:[SSL::sessionid]".
- Irene_Garcia-An
Nimbostratus
It looks very fine, thanks. I have implemented and will test with users
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com