Forum Discussion
djkromarek
Nimbostratus
May 18, 2012IP's allowed with Application security
I am trying to find out the following information. I have BIG-IP 9.4.7 Build 320.1 Final. I have the Application Security Module on this configuration. Is it possible, to add a list of IP's that the F5 will allow through and block all other IP's? Thanks, Deni
7 Replies
- santosh_81454
Nimbostratus
You can do this an iRule on the LTM module using the "IP::client_addr" parameter.
Please refer this article: https://devcentral.f5.com/wiki/irules.IP__client_addr.ashx
-Santosh. - djkromarek
Nimbostratus
How much overhead will be created on the F5 if I need to create the iRule with 1000 IPs to allow and everything else to be blocked? Can something be done using geolocation instead? - santosh_81454
Nimbostratus
You can create a Data group and use an external class file to list the IPs.
So are you having 1000 unique IP's, can you try consolidating into networks using subnet masks ?
And for your next question, No, I dont think ASM or LTM can filter traffic based on geo location. But other product of F5 called the GTM has the capability to filter traffic based on geo location.
Hope this helps.
-Santosh. - BT_90520
Nimbostratus
Something that you may be interested
LTM and GTM
- Geolocation iRules to do it (https://devcentral.f5.com/Tutorials/TechTips/tabid/63/articleType/ArticleView/articleId/1082330/New-Geolocation-Capabilities-in-v101.aspx)
....more GTM (topology) http://support.f5.com/kb/en-us/solutions/public/13000/400/sol13412.html
....more LTM (Packet filter) http://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/bigip-datacenter-firewall-config-11-1-0/5.htmlunique_1529505549
ASM (Enforcing application use in certain geolocations)
- http://support.f5.com/kb/en-us/products/big-ip_asm/manuals/product/asm-implementations-11-1-0/5.htmlconceptid - djkromarek
Nimbostratus
Do you have a link to instructions on how to create a Data group and use an external class file to list the IPs? this sounds like our best bet on trying to get this configured. At this time, we cannot upgrade to the correct version in order to use the GTM.
Thanks! - djkromarek
Nimbostratus
Thank you for the articles, they were very informative. The Geolocation may not be our best bet at this time since we are on version 9.4, however we do plan on upgrading this year and these articles will be very useful then. I appreciate your response. - santosh_81454
Nimbostratus
This article discusses about Data Groups:
http://support.f5.com/kb/en-us/solutions/public/3000/300/sol3386.html?sr=21443170
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects