Aug 04, 2011

iRule to Filter on X-Netli-Forward-For value

I am trying to create an iRule that will look at the X-Netli-Forward-For value, and if it matches an IP address, it is forwarded on, if it does not, it is dropped. Basically, I only want to allow a global PAT to to be forwarded on from the VIP, and everything else to drop. Any help would be appreciated. Thanks.

  • If you create an address type datagroup you can use an iRule like this. Keep in mind that users can insert any arbitrary header. So if someone knew you were using this kind of logic they could bypass it.

  • Thanks for the replies. There are actually two globals, so the data group suggestion by Aaron worked out great. Also, good call out on the header insertion. Thanks again.