Forum Discussion
Adi82_183873
Nimbostratus
Jan 23, 2015iRule and data group not matching properly
Hi all,
We have the following devices:
2 BIG-IPs version is version 11.4.1. HA enabled.
Network topology is :
Akamai --- BIG-IP --- WAF --- Servers HTTP
The issue is :
1) We have several...
Arie
Altostratus
Jan 23, 2015@LyonsG is right - you want to use "type ip" and preferably netmasks.
A couple of questions:
- Where does the value for "True-Client-IP" come from?
- Is there a specific reason you're inserting XFF via an iRule instead of in the HTTP-Profile?
- Is there a specific reason you're using a header value to get to the client IP address (vs. using
)?IP::client_addr - Wouldn't it be better to return a 503 (Service Unavailable) instead of a 302 (Temporary Redirect) followed by (presumably) a 200 (OK)?
- How are you activating the maintenance rule? (if you're changing the iRule that may not affect existing connections).
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects