Explanation of F5 DDoS threshold modes
Der Reader, In my article “Concept of Device DOS and DOS profile”, I recommended to use the “Fully Automatic” or “Multiplier” based configuration option for some DOS vectors. In this article I would...
Published Feb 12, 2020
Version 1.0Sven_Mueller
Ret. Employee
Joined February 03, 2011
Sven_Mueller
Ret. Employee
Joined February 03, 2011
dragonflymr
Oct 05, 2021Cirrostratus
One more question about using different State settings. Could you share some real life examples when to use:
- Learn Only - my understanding is that it's useful when DDoS is first enabled and when Full Automatic/Auto Detection mode is planned to be used in the future. Does it make any sense if Full Manual will be used?
- Detect Only - seems to be more useful as it creates Alerts (in opposite to Learn Only) so it allows for better understanding if there are attacks or what could be false positive
You never mentioned Manual Detection/Auto Mitigation - is that because this mode is not really useful?
Piotr