Forum Discussion
Adi82_183873
Nimbostratus
Jan 22, 2015iRule and data group not matching properly
Hi all,
We have the following devices:
2 BIG-IPs version is version 11.4.1. HA enabled.
Network topology is :
Akamai --- BIG-IP --- WAF --- Servers HTTP
The issue is :
1) We have several...
Arie
Altostratus
Jan 23, 2015@LyonsG is right - you want to use "type ip" and preferably netmasks.
A couple of questions:
- Where does the value for "True-Client-IP" come from?
- Is there a specific reason you're inserting XFF via an iRule instead of in the HTTP-Profile?
- Is there a specific reason you're using a header value to get to the client IP address (vs. using
)?IP::client_addr - Wouldn't it be better to return a 503 (Service Unavailable) instead of a 302 (Temporary Redirect) followed by (presumably) a 200 (OK)?
- How are you activating the maintenance rule? (if you're changing the iRule that may not affect existing connections).
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects