For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Peo's avatar
Peo
Icon for Nimbostratus rankNimbostratus
Sep 24, 2019

Reset connection via iControl

Hi!

 

I have written an AI that does some analyzing and sometimes decides that an IP no longer should be

allowed to access a specific resource.

 

When this happens, the IP is added to a data-group-list and the resource has an iRule that checks if

the IP is blocked via the CLIENT_ACCEPTED-event.

 

Problem: The current connection is allowed to persist since the drop in only done when a new connection

is set up (due to using the CLIENT_ACCEPTED-event).

 

I have been looking through the iControl API to see if I can drop a specific connection based on IP but

I can't find anything about networking at all.. Any ideas how to solve this?

 

Since the resource get a lot of request, it would not be very good to check the DGL on every incomming request.

 

Product: BIG-IP

Version: 13.1.1

Build: 0.0.4

BIG-IP 4000S