Forum Discussion

peevuto_71256's avatar
peevuto_71256
Icon for Nimbostratus rankNimbostratus
Sep 26, 2008

Number of Websites?

An LTM-8800 with the ASM module. I have 600+ unique websites that need protecting, and each has their own IP address, non-contiguous.

 

 

Other WAF solutions limit the number of websites due to granularity reasons. How many physical and unique websites can the F5 ASM handle. The SE has told me he has seen as many as 50 sites behind the ASM, but couldn't speak whether it could handle more. Throughput aside, I need to know how many boxes I would need to protect and provide detailed reporting for 600+ websites. There must be a limit... what is it?

 

 

Thanks

2 Replies

  • Hi Peevuto,

     

     

    I think the limiting factors for ASM are probably some of these below and not necessarily the number of policies, VIPs or pools configured:

     

     

    - requests / second

     

    - size of requests / responses

     

    - latency in client requests and, more significantly, server responses

     

    - complexity of the policy: are you checking a lot of parameters, are you validating parameters set by the app in subsequent requests (dynamic parameters), are you using every attack signature, etc.

     

     

    From a manageability perspective, I think it would be difficult to configure and maintain 600 separate policies. I'd try developing one policy per type of architecture rather than per website you want to protect. The only time I'd use a new policy for a web app of the same architecture as an existing set of apps is if the security requirements were significantly different.

     

     

    It's extremely difficult to give accurate sizing recommendations with ASM because there are so many variables involved. I'd try going back to your F5 SE and give them as much detail as you can on your use case and see if they can suggest rough numbers. Else, the most accurate answer might come from testing your potential configuration in a QA environment.

     

     

    You might also consider posting this in the Performance Testing forum (Click here). Maybe Mike or someone else has done testing which would be relevant to your scenario.

     

     

    Aaron
  • I'm interested to hear more about your ASM experiences so far. It sounds like our organizations are very similar in terms of the number of web sites we want ASM to protect. We currently have 5 LTM pairs, and one of those pairs has close to 700 virtual servers for web applications - most will need ASM protection.