cancel
Showing results for 
Search instead for 
Did you mean: 
Graham_Alderso1
F5 Employee
F5 Employee

Problem this snippet solves:

This code enables you to bypass Proactive Bot Defense for a specific bot signature.

Caution: If the signature is simple, it may be easy for an attacker to guess it and craft a response to match the signature and thus bypass Proactive Bot Defense with this in place. For this reason, another bypass solution is recommended where possible. You can bypass Proactive Bot Defense without this iRule by setting a benign category to "Report" and ensuring that the signature has a reverse DNS lookup in place. This will validate the source in addition to other factors such as the User-Agent.

How to use this snippet:

Add to the virtual server that is protected by Proactive Bot Defense and Bot Signatures. Enter the signature you want to bypass in the code where the example "curl" is placed currently. The signature's category must be set to report or block for this to take effect. Tested on v13.1.

Code :

when BOTDEFENSE_ACTION {
  #log local0. "signature: [BOTDEFENSE::bot_signature]"
  if { [BOTDEFENSE::bot_signature] ends_with "curl"} {
    BOTDEFENSE::action allow
  }
}
Version history
Last update:
‎30-May-2018 13:39
Updated by:
Contributors