Forum Discussion
kongfranon_5200
Nimbostratus
Jul 28, 2010rate limit - too many bad logins
Is there a way to setup an iRule to limit ip address if they try to login to a particular URL too many times but getting denied becuase of wrong password or username, and then deny them access for a certain period of time?
I am very new to F5, and still trying to understand it.
Thanks in advance
- Chris_Miller
Altostratus
The ability definitely exists...someone more versed than I would have to write the rule. You'd basically have to increment a counter based on a certain response string from the server. - hoolio
Cirrostratus
As Chris suggests, you could use an iRule implement the checks you've described. This wouldn't be a simple iRule, but it could be done. It would be a lot simpler and efficient if you're running (or able to upgrade to) 10.1 or higher as you'll be able to use the table command to track the client IP addresses. Keep in mind that if you have a lot of clients connecting from behind the same proxy address, you could potentially block legitimate users who share the same proxy.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects