Forum Discussion
Using X-API-Key header to secure an LTM pool of API servers
Is it possible to use any of the modules on a BIG-IP to secure a pool of API servers. I'm guessing at an APM or iRule solution but struggling to find examples. We have ASM, APM and LTM modules installed. The current solution thinking being client servers from a third party would use the X-API-Key header in their HTTPS requests to our API, we aren't considering OAuth at this time due to the added complexity. Any thoughts would be most welcome.
Hi,
you can use an irule to retrieve the header valie and then use either a sideband connection to validate the token or an access policy using ACCESS::policy evaluate command with an access profile containing a HTTP AAA server to validte the token
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com