Manual Chapter : Managing Allowed Network Addresses under DoS Protection

Applies To:

  • BIG-IQ Centralized Management

    8.4.0, 8.3.0, 8.2.0, 8.1.0, 8.0.0

Managing Allowed Network Addresses under DoS Protection

You create network allowlists to bypass checks in a DoS profile.

  1. Click Configuration > SECURITY > Shared Security > DoS Protection > Network Allow Lists.

  2. Click the name of the BIG-IP ®device on which to create the network allowlist.

  3. In the Allowlist Address List setting, select the IP address from which the packet is coming.

  4. Click Create to add a network allowlist.

  5. Type a Name for the network allowlist, and an optional Description that will be useful in your environment.

  6. In the Protocol setting, leave the default value, Any, or select the appropriate network protocol.

  7. In the VLAN setting, leave the default value, Any, select the appropriate VLAN, or select Other and provide a VLAN tag number.

  8. For the Address Type setting, specify the type of addresses being handled: Source or Destination.

    The properties available change based on your choice.

  9. In the Source area Address setting, leave the default value, Any, or select the field to the right and provide the address.

    You can specify IPv4 or IPv6 addresses in CIDR notation as the address. You can specify a source address or destination address, but not both in the same allowlist entry.

  10. In the Destination area Address setting, leave the default value, Any, or select the field to the right and provide the address.

  11. In the Destination area Port setting, leave the default value, Any, or select the appropriate port.

    The system provides the default port number value for each port type when the Protocol is set to TCP or UDP.

  12. When you are finished, click OK.

  13. Save your changes.