Forum Discussion
John_Krum
Cirrus
Oct 03, 2022Can you stop RST from being sent by VIP
I work for a large regional public transportation company. We are in the beginning process of rolling out phones with a VoIP over the top application on them. This will eliminate the need for radios ...
Kevin_Stewart
Employee
Oct 05, 2022At the very least, you have a VIP with the correct IP, but wrong port. That's what is causing the RST response.
Kevin_Stewart
Employee
Oct 05, 2022I'll add, as the RST is not specifically coming from the VIP, since that VIP isn't listening on the correct port, you'd likely need something global to control behavior. There are also a few additional options:
- AFM (Advanced Firewall Manager) could be employed in a Global scope to discard any traffic that does not match the listening port(s).
- For simpler tasks, a packet filter rule could be used.
- Packet Filtering: enabled
- Unhandled Packet Action: Discard
- Rules
- Action: Accept
- VLAN / Tunnel: * All
- Filter Expression: { dst port 53 }
You'll need to tweak the packet filter rules to your environment, but this could effectively be used to discard any traffic coming to the BIG-IP that doesn't match a listening port.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects