Forum Discussion
puneet_mandyal_
Nimbostratus
Mar 28, 2018SFTP port 22 to be allowed on specfic IP addresses
Hi All,
We have SFTP allowed on f5 and we need to narrow down the access parameter to hit by specific IP address
How We can create rule for SFTP allow on specific IP addresses
oguzy
Cirrostratus
Mar 28, 2018Hi,
You can use Data Groups within an irule.
For instance;
when CLIENT_ACCEPTED {
Comparing source IP to a list of entries in a LTM data-group.
if { not ( [class match [IP::remote_addr] equals data_SourceIps ] ) } {
reject;
}
}
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects