Forum Discussion
Inquiries about Advanced WAF DoS Protection
As you're referring to Advanced WAF, it's important to note that it only addresses Layer 7 (L7) DDoS attacks, where 1 HTTP request is considered as 1 transaction.
Attacks such as SYN floods or Smurf (ICMP) attacks are not handled by Advanced WAF, as they occur at lower layers. For these types of attacks, you should consider using LTM (for basic TCP protection) or AFM (for full Layer 3/4 DoS protection).
In such cases, each SYN or ICMP packet is counted as 1 transaction.
Mitigation is automatically lifted once the TPS rate drops below the configured threshold.
Regarding X-Forwarded-For (XFF) headers, ASM uses the first IP address in the list
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com