Block IP Addresses With Data Group And Log Requests On ASM Event Log
Problem this snippet solves: This is Irule which will block IP Addresses that are not allowed in your organization.
instead of adding each IP Address in Security ›› Application Security : IP Addre...
Published Feb 17, 2019
Version 1.0Michael_Michael
Nimbostratus
Joined May 05, 2019
Michael_Michael
Nimbostratus
Joined May 05, 2019
renaranj2024
Nimbostratus
It's missing this step: Security>>Application Security: Policy Building:Learning and Blocking Settings
search for Custom Violations section and enable Alarm and Block settings for the just created violation Illegal_IP_Address.
Tested on version 16.1.4.x
1982
Apr 24, 2024Nimbostratus
renaranj2024 is possible to create a new how-to using your version?
- renaranj2024Apr 24, 2024Nimbostratus
Use this procedure and add the two steps I wrote.
The Code works fine. Use you datagroup name and custom violation name.
- 1982Apr 24, 2024Nimbostratus
Ok, I'll try to use it, the same code from the example, my concern is blocking everything, not just the Black_list IPs, but all sources.