Manual Chapter : Managing Device DoS in Shared Security

Applies To:

Show Versions Show Versions

BIG-IQ Security

  • 4.5.0
Manual Chapter

About device DoS

You can use the Device DoS panel to manage your devices response to DoS attacks, including having a network white list.

To get help on any panel, click the (?) icon in the upper right corner.

Importing devices

You do not import devices using the BIG-IQ system; instead,you export them from BIG-IP systems to the BIG-IQ system.

Editing devices

Hover over the header of the device you want to edit, when the gear icon appears, click it and select Properties to expand the panel.

Editing device DoS

Use the Device DoS panel to edit and view the device DoS properties.

  1. Hover over the header of the device you want to edit and when the gear icon appears, click it and select Properties to expand the panel.
  2. Modify the device properties as needed. Note that not all properties can be modified. Some properties are read-only.
    • Use the Device Configuration settings to view values within the configuration.
    • Use the Network Whitelist settings to add, delete or modify whitelist entries.
  3. When you are finished, click Save to save changes and exit the panel.

Editing device configuration entries

You edit device configuration entries using the Device Configuration settings.

  1. Locate the configuration category containing the entry to modify, click the + at the end of it. The category expands.
  2. Click the value to change and then edit it.
  3. To end the edit mode, click the check mark ( )at the end of the entry; to cancel the change, click the X at the end of the entry.
  4. Click Save to save changes and exit the panel.

Adding network whitelist entries

You add network whitelist entries using the Network Whitelist settings.

  1. Click Network Whitelist and then clickAdd new. The Edit/Add properties screen displays. Only 8 whitelist entries can exist at a time.
  2. Type or modify the properties as needed. You can specify IPv4 or IPv6 addresses in CIDR notation as values to the address fields. You can specify a source address or destination address but not both in the same whitelist entry.
  3. Click Done to complete the whitelist entry.
  4. Click Save to save changes and exit the panel.

Editing network whitelist entries

You edit network whitelist entries using the Network Whitelist settings.

  1. Click the edit icon at the end of the row containing the whitelist to edit. The Edit/Add properties screen displays.
  2. Modify the properties as needed and click Done.
  3. Click Save to save changes and close the screen.

Deleting network whitelist entries

You delete network whitelist entries using the Network Whitelist settings.

  1. Select the check box to the left of the whitelist you want to delete.
  2. Click Delete on the Network Whitelist tab.
  3. Click Save to save changes and exit the screen.