Forum Discussion
Faintly_Lucky
Nimbostratus
May 21, 2010Port Lockdown
Hi:
Really stupid simple question here, but I want to make sure that I have my facts straight on port lockdown before I implement it and I've never worked with it before, so I don't want to upset any of my customers.
The way I understand port lockdown, it only involves traffic that is sourced from a host with the destination address being the F5's self-IP. So if you set the port lockdown setting to None, the Self-IP won't accept any connections with itself as the destination, but traffic going through the Self-IP with another destination will flow just fine ( from a server trying to talk to www.mydomain.com that has F5 set as its default gateway).
Is that correct?
1 Reply
- nathe
Cirrocumulus
FL
That's how I understand it. Port Lockdown is used to limit access the self-ip address itself, rather than the scenario you outline. It's a feature to secure the interface.
One thing to mention - if the system is part of a redundant pair then Allow Default is the suggested option. If you click on Help on that screen it will give you a list of the allowed protocols / services when this is selected.
N
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
