Forum Discussion
Portscan detected from f5 snatpool?
Hi Dario,
Thanks! Ill give it a try once we see it happening again. There is otherwise no logging which i can check to figure out the origin adres?
Kr,
Zero.
Hello Zero27351.
There are no records for old flows, but you can create an iRule for logging those sessions and apply it to the VS. Or even better, create a Request-Logging profile.
Logging connections using High Speed Logging
https://github.com/DariuSGB/F5_iRules/blob/master/HSL_Logging.tcl
Request logging profile
https://support.f5.com/csp/article/K00847516
In both cases, I recommend you send those logs to an external device, to not affect the local system performance.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com