Forum Discussion
Portscan detected from f5 snatpool?
Hello Zero27351.
If the connection is currently active, you could check the connections table to figure out the origin.
show sys connection ss-client-addr <SNAT_IP>
- Zero27351Apr 20, 2022Altostratus
Hi Dario,
Thanks! Ill give it a try once we see it happening again. There is otherwise no logging which i can check to figure out the origin adres?
Kr,
Zero.
- Apr 21, 2022
Hello Zero27351.
There are no records for old flows, but you can create an iRule for logging those sessions and apply it to the VS. Or even better, create a Request-Logging profile.
Logging connections using High Speed Logging
https://github.com/DariuSGB/F5_iRules/blob/master/HSL_Logging.tcl
Request logging profile
https://support.f5.com/csp/article/K00847516
In both cases, I recommend you send those logs to an external device, to not affect the local system performance.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com