Forum Discussion
Brian_Mayer_841
Nimbostratus
Nov 05, 2007Restrict access to Virtual Servers based on IP address
Hi all,
We have some test sites going online soon and need them to be publicly accessible for some external testers. But we don't want the entire world to see the sites until they're ready ...
hoolio
Cirrostratus
Nov 07, 2007I think the issue is that you're testing this on a virtual server with a pool, but you're using the forward command. If you want the BIG-IP to load balance the requests, don't use the forward command. You actually don't have to do anything in the case that the client IP matches the IP's/networks in the datagroup. If the client IP doesn't match, then you want to send a reset back to the client using the reject command.
I'm not sure what cause the error when trying to add a datagroup using the iRuler. You might try posting the error and any other details in the iRuler forum for Joe to take a look at.
Datagroups (known as classes in the bigip.conf config file) are separate objects from rules. If you want to create another datagroup, you should be able to using the iRuler or in the admin GUI under Local Traffic >> iRules >> Datagroups.
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects