Forum Discussion
Mike_Maher
Nimbostratus
Dec 21, 2012iRule or Custom Attack Signature??
I am wanting to configure something to looks for the following patterns that pertain to recent DDoS attackes that have been going around and log the event.
ยท UDP packets containing this...
Ido_Breger_3805
Dec 22, 2012Historic F5 Account
Hi Mike,
ASM signatures can detect that within HTTP requests, however, from what you describe (especially the need for UDP), it seems that this isn't part of HTTP.
The general advice is to use ASM for anything that is HTTP related (ASM sigs are faster than iRules) and iRules for anything else.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects