Updated Date: 07/07/2026
Configuring Bot Defense in Advanced Service Level
Before configuring Bot Defense you need to configure a Proxy pool or Protection pool, or select an existing pool during configuration. For more information, refer to BIG-IP Local Traffic Management: Basics - Introduction to pools.
Use this task to configure the Bot Defense in Advanced/Premium service level for protecting web pages.
Note: The screen elements described here are for basic configuration. Refer to the help text available in the configuration utility for details about all the fields.
-
On the Main tab, click Distributed Cloud Services > Bot Defense > BD Profiles.
The BD Profiles screen displays the list of Bot Defense profiles on the system.
-
In the General Properties section, enter the following details:
-
In the Profile Name field, enter a unique name for the Bot Defense profile.
-
In the Parent Profile field, select the Bot Defense parent profile from which this profile will inherit settings.
-
For the Service Level field, select Advanced / Premium.
-
For the Application Type field, check Web.
-
-
In the API Request Settings section, in the Import API Settings field, check Upload File and click the Choose File button to import a JSON file with predefined values or check Paste Text to enter the JSON file content. The contents of the file must be in a valid JSON format.
-
In the JS Insertion Configuration section, the BIG-IP Handles JS Injections field is checked by default, if you uncheck the field then follow the Note given in the Web UI.
-
In the Protected Endpoint - Web section, enter the following details:
Note: The GET (Document) field is checked only when the Bot Defense is required for web scraping.
-
In the Mitigation Handler field, select
BIG-IPif you want to handle the mitigation actions or selectAdvanced / Premium Policyto let the system handle the mitigation of malicious HTTP requests. -
In the Protected URIs field, enter the following details and click the Add button:
-
In the Path field, enter the path to the web page.
-
Check the ANY Method field to protect the path when it has any method.
Note: You must check (enable) at least one of the methods or ANY Method field, else, the HTTP requests will not be routed.
-
Check the GET (XHR/Fetch) field to protect the path when it has a GET method.
-
Check the POST field to protect the path when it has a POST method.
-
Check the PUT field to protect the path when it has a PUT method.
-
In the Mitigation Action field, choose the mitigation action you want the BIG-IP to take if a malicious HTTP request is detected on the endpoint.
Note: The Mitigation Action field is available only when
BIG-IPis selected in the Mitigation Handler field.
Click the Add button to add the URI. You can add multiple URIs, use the Edit and Delete buttons to update or delete a URI from the list.
-
-
-
In the Advanced Features section, select
Advanced, enter the following details:-
Check the Use Proxy field if you want the data to be routed through a proxy server, else uncheck this field to send data directly from the BIG-IP to the Bot Defense backend server.
-
In the Proxy Pool field, select an existing pool or click the + button to add a new pool.
Note: The Proxy Pool field is displayed when the Use Proxy field is checked.
-
In the Proxy Bot Protection Endpoint URL field, enter the web URL that is used to redirect HTTP requests to the Bot Defense backend server.
Note: The Proxy Bot Protection Endpoint URL field is displayed when the Use Proxy field is checked.
-
In the Protection Pool field, select an existing pool or click the + button to create a new pool. If you click the + button, the pool configuration screen appears. In the pool configuration screen, create a new pool using the IP or domain of the bot server. When you click Finish in the pool configuration screen, you return to the BD Profile screen.
Note: The Protection Pool field is displayed when the Use Proxy field is unchecked.
Important: While creating a pool, ensure to manually select an applicable FQDN based on location, following are a few examples:
- Select
ibd-webemea2.fastcache.netfor EMEA. - Select
ibd-webus.fastcache.netfor US. - Select
ibd-webapcj.fastcache.netfor APCJ.
- Select
-
In the SSL Profile field, select the server-side SSL profile.
-
Check the CORS Support field to let the Cross-Origin Resource Sharing (CORS) protocol to allow the restricted resources on a web page to be requested from another domain outside the domain from which the first resource was served.
-
Check the Report Transaction Result field to enable reporting the transaction results to improve bot defense.
-
-
Click the Finished button.
The Bot Defense profile is created.
Assign the Bot Defense profile to Virtual Server, refer to Assigning a Bot Defense profile to Virtual Server.
Before configuring the Bot Defense for web scraping (interstitial), configure the Bot Defense profile in Advanced/Premium service level for web and update the Protected URIs field, refer to Configuring Bot Defense in advanced service level for web.
Use this task to configure the Bot Defense in Advanced/Premium service level for protecting traffic from web scraping.
-
On the Main tab, click Distributed Cloud Services > Bot Defense > BD Profiles.
The BD Profiles screen displays the list of Bot Defense profiles on the system.
-
Click the Bot Defense profile for which web scraping is configured.
-
In the Protected Endpoint - Web section, enter the following details:
-
In the Mitigation Handler field, select
BIG-IPif you want to handle the mitigation actions or selectAdvanced / Premium Policyto let the system handle the mitigation of malicious HTTP requests. -
In the Protected URIs field, enter the following details and click the Add button:
-
In the Path field, enter the path to the web page.
-
Check the GET (Document) field to protect the path from web scrapping.
Note: When you check (enable) GET (Document) field, no other method can be enabled.
-
In the Mitigation Action field, choose the mitigation action you want the BIG-IP to take if a malicious HTTP request is detected on the endpoint.
Note: The Mitigation Action field is available only when
BIG-IPis selected in the Mitigation Handler field.
Click the Add button to add the URI. You can add multiple URIs, use the Edit and Delete buttons to update or delete a URI from the list.
-
-
-
Click the Update button.
Before configuring Bot Defense you need to configure a Proxy pool or Protection pool, or select an existing pool during configuration. For more information, refer to BIG-IP Local Traffic Management: Basics - Introduction to pools.
Use this task to configure the Bot Defense in Advanced/Premium service level for mobile applications. If you want to configure Bot Defense for both mobile and web in the same profile, then in Application Type field check Web and Mobile and configure respective screen elements. Use Configuring Bot Defense in advanced service level for web task for reference.
Note: The screen elements described here are for basic configuration. Refer to the help text available in the configuration utility for details about all the fields.
-
On the Main tab, click Distributed Cloud Services > Bot Defense > BD Profiles.
The BD Profiles screen displays the list of Bot Defense profiles on the system.
-
Click the Create button.
The New BD Profile screen opens.
-
In the General Properties section, enter the following details:
-
In the Profile Name field, enter a unique name for the Bot Defense profile.
-
In the Parent Profile field, select the Bot Defense parent profile from which this profile will inherit settings.
-
For the Service Level field, select
Advanced / Premium. -
For the Application Type field, check
Mobile. TheWebis checked by default, you can uncheckWebif the Bot Defense profile is only used to protect mobile application. You can leave theWebas checked, if the Bot Defense profile is used to protect both web page and mobile application.
-
-
In the API Request Settings section, in the Import API Settings field, check Upload File and click the Choose File button to import a JSON file with predefined values or check Paste Text to enter the JSON file content. The contents of the file must be in a valid JSON format.
-
In the Protected Endpoint - Mobile section, enter the following details:
-
In the Mitigation Handler field, select
BIG-IPif you want to handle the mitigation actions or selectAdvanced / Premium Policyto let the system handle the mitigation of malicious HTTP requests for mobile application. -
In the Protected URIs field, enter the following details and click the Add button:
-
In the Path field, enter the path to the mobile application.
-
Check the ANY Method field to protect path the when it has any method.
Note: You must check (enable) at least one of the methods or ANY Method field, else, the HTTP requests will not be routed.
-
Check the GET field to protect the path when it has a GET method.
-
Check the POST field to protect the path when it has a POST method.
-
Check the PUT field to protect the path when it has a PUT method.
-
Use the Check Mobile Identifier field if the URL is same for web and mobile, select
Headerto request the information, or selectSkipto ignore. -
In the
Mitigation Actionfield, choose the mitigation action you want the BIG-IP to take if a malicious HTTP request is detected on the endpoint.Note: The Mitigation Action field is available only if the Mitigation Handler field is set to BIG-IP.
Click the
Addbutton to add the URI. You can add multiple URIs, use theEditand Delete buttons to update or delete a URI from the list. -
-
In the SDK Reload Headername filed, enter the reload header prefix.
-
In the SDK Config Fetch URL - Android, enter the URL to fetch SDK configuration for android.
-
In the SDK Config Fetch URL - iOS, enter the URL to fetch SDK configuration for iOS.
-
-
In the Advanced Features section, select Advanced, enter the following details:
-
Check the Use Proxy field if you want the data to be routed through a proxy server, else uncheck this field to send data directly from the BIG-IP to the Bot Defense backend server.
-
In the Proxy Pool field, select an existing pool or click the + button to add a new pool.
Note: The Proxy Pool field is displayed when the Use Proxy field is checked.
-
In the Proxy Bot Protection Endpoint URL - Mobile field, enter the application URL that is used to redirect HTTP requests to the Bot Defense backend server.
Note: The Proxy Bot Protection Endpoint URL - Mobile field is displayed when the Use Proxy field is checked.
-
In the Protection Pool - Mobile field, select an existing pool or click the + button to add a new pool. If you click the + button, the pool configuration screen appears. In the pool configuration screen, create a new pool using the IP or domain of the bot server. When you click Finish in the pool configuration screen, you return to the BD Profile screen.
Note: The Protection Pool - Mobile field is displayed when the Use Proxy field is unchecked.
Important: While creating a pool, ensure to manually select an applicable FQDN based on location, following are a few examples:
- Select
ibd-webemea2.fastcache.netfor EMEA. - Select
ibd-webus.fastcache.netfor US. - Select
ibd-webapcj.fastcache.netfor APCJ.
- Select
-
In the SSL Profile field, select the server-side SSL profile.
-
Check the CORS Support field to let the Cross-Origin Resource Sharing (CORS) protocol to allow the restricted resources on a web page to be requested from another domain outside the domain from which the first resource was served.
-
Check the Report Transaction Result field to enable reporting the transaction results to improve bot defense.
-
Assign the Bot Defense profile to Virtual Server, refer to Assigning a Bot Defense profile to Virtual Server.