Forum Discussion

philyeo_72087's avatar
philyeo_72087
Icon for Nimbostratus rankNimbostratus
Feb 24, 2015

ASM DoS Protection and Trust-XFF-Header

Does anyone know if the ASM DoS Protection will respect the IP Address defined the the ASM Policy Configuration (Advanced), where you can enable "Trust XFF Header" which specifies the HTTP Header to use that contains the IP of the end client?

 

e.g. If there is traffic coming in from many end clients through a trusted proxy which inserts the end user IP Address into a HTTP Header, then if we define the ASM Policy to use this header, and then define a DoS Protection Profile set to use Source IP-Based Rate limiting, then will this rate limit apply to the connections from the proxy or from each end user?

 

1 Reply

  • You should be able to do this by enabling "Accept XFF" on the HTTP profile (Local Traffic>Profiles>Services>HTTP> Properties. This ensures the DoS profile will trust the XFF you specify, rather than the security policy. This method started with v11.5.1.