This solution provides an enterprise-grade F5 BIG-IP iApp template and enforcement engine that automates the ingestion of Threat Intelligence Indicators of Compromise (IOCs) from:
- STIX 2.1 / TAXII 2.1 servers
- Remote HTTP/HTTPS feeds
- Local files
The solution provides real-time L4/L7 threat blocking on selected Virtual Servers permitting to define which Application to protect and the prefered ingestion method to use.
Key Features:
- 100% Self-Contained Deployment: The iApp template embeds the complete Python ingestion engine as a Base64 payload. Deploying the template automatically provisions /shared/scripts/stix_taxii_importer.py with executable permissions on the BIG-IP without requiring manual file transfers over SSH/SCP.
- Virtual Server Protection Modes: Specify existing target Virtual Server(s) or deploy in standalone mode (Data Groups & background polling only).
- Automated Multi-Source Threat Feed Ingestion:
- OASIS TAXII 2.1: Connects to discovery roots and collection endpoints with dynamic API root traversal and strict RFC headers.
- MISP Threat Feeds: Direct ingestion of Threat feeds in JSON format, with automated multi-bulletin aggregation via manifest.json.
- Local PC File Upload: Direct support for files uploaded through TMOS GUI (System > File Management > Data Group File List > Import).
- Plain Text / CSV Feeds: Supports custom blocklists in the plain text / CSV format.
- Export of threat feeds using secure cli connection or via Data Group Export.
Deployment Options
Step 1: Import the iApp Template
- In the BIG-IP GUI, navigate to iApps > Templates > Templates.
- Click Import….
- Select stix_taxii_blocker.iapp.tmpl and click Upload.
Step 2: Instantiate the iApp Service
- In the BIG-IP GUI, navigate to iApps > Application Services > Applications.
- Click Create….
- Select stix_taxii_blocker from the Template dropdown.
- Configure the parameters.
- Click Finished.
| Section | Parameter | Description |
|---|---|---|
| Virtual Server | Protection Mode | Choose Protect an Existing Virtual Server or Standalone |
| Target Virtual Server | Select the Virtual Server to protect (e.g. /Common/vs_https) | |
| Inspect XFF | Enable to inspect X-Forwarded-For headers behind CDNs/proxies | |
| Threat Feed | Source | Choose TAXII 2.1 Server, Remote Threat Feed URL, or Uploaded File / BIG-IP Local File |
| TAXII URL | Base URL of TAXII 2.1 discovery or collection endpoint | |
| Collection ID | Optional collection identifier (e.g. malicious-indicators) | |
| Remote Feed URL | URL of MISP JSON, ThreatFox CSV/JSON, or plain text blocklist | |
| Uploaded / Local File | Name of file imported in System > File Management or local file path | |
| Authentication | Select None, Basic Auth, Bearer Token, or API Key | |
| Polling Schedule | Choose synchronization interval (e.g., Every 5 min, 1 hour, 24 hours) | |
| Outbound Proxy | Optional egress proxy URL (e.g., http://proxy.corp:8080) | |
| Actions | Action for Malicious IPs | Silently Drop, Send TCP Reset, or Log Only |
| Action for Malicious URLs | Return Responsive 403 Block Page, Drop, Reset, or Redirect | |
| Whitelists | IP Whitelist Table | Enter corporate subnets to exempt (e.g., 10.0.0.0/8, 192.168.1.0/24) |
| URL Whitelist Table | Enter internal domains or bypass paths (e.g., internal.corp, /healthcheck) |
The iApp will automatically:
- Self-deploy the Python ingestion engine to /shared/scripts/stix_taxii_importer.py.
- Ingest initial threat intelligence data and populate external Data Groups.
- Generate and bind the optimized L4/L7 enforcement iRule to your Virtual Server.
- Configure scheduled background polling via iCall / cron.
If you want to remove one of the instantiated iApp service:
- Reconfigure the iApp
- Move “Attach mode” to Standalone (this will remove the protection from the VS)
- Click Finished.
- Delete the instantiated iApp
