Forum Discussion
JRahm
Dec 30, 2021Admin
if you are not using AFM, this is probably fine. If you are, you might need to move some of that geolocation logic earlier, as it's processed before ASM (see here). But to your specific question on automating this, if amazon has an api where you can get those addresses, you can pull that on a cron frequency, and then use iControl REST to push those to your policies. Example (just put placeholder values on those attributes, you'd need to set appropriately for your environment):
- AndréBJan 03, 2022Nimbostratus
Hi Jason,
Best wishes for 2022.
We're not using AFM, so that's fine.
The AWS ip ranges and updates on it, can be dowloaded in a Json file.
I'll try to get it working using iControl REST.
Thank you for the reply.