You can install DDoS Hybrid Defender™ onto a dedicated system approved for
the software. You can deploy the system inline or out-of-band. For out-of-band deployments, you
can set up the system in one of two ways: as a span port or using NetFlow. A span port analyzes
mirrored packets, and NetFlow listens for and reviews metadata.
Before you start, you must have assigned the management IP address on the LCD panel of the
device, or with a hypervisor if using the Virtual Edition. This procedure is for installing a
single, stand-alone DDoS Hybrid Defender system to protect against DDoS attacks. If you have two
systems and want to install them for high availability, follow the steps described in
Installing DDoS Hybrid Defender for High Availability.
Make sure you have this information available:
- Base registration key
- Internal and external self-IP addresses
- Management IP address, network mask, and
management route IP address
- Passwords for the root and admin accounts
- NTP server IP address (optional)
- Remote DNS lookup server IP address (required for F5 Silverline®
integration or if resolving host names)
Installing DDoS Hybrid Defender
Before you begin, you need to have
access to the DDoS Hybrid Defender™ software from F5 (either on the
system or downloaded from F5), and have completed the initial setup.
You can install DDoS Hybrid Defender on the system.
Log in to DDoS Hybrid Defender with the administrator user name and
The system displays the Welcome screen.
On the Main tab, click DoS Protection.
From the Install Method list, select Use
If the software is not on the device, you need to download the RPM onto your
local system from F5 Downloads, then select Upload RPM to
locate and upload that file.
The software is installed quickly, and the Protected Objects screen
The DDoS Hybrid Defender software is installed. The next time you log in, you will be
able to access the DoS Protection screens.
Next, you can begin configuring the network, then setting up DDoS Hybrid Defender to
protect your networks and web applications from DoS attacks.
Connecting with F5 Silverline
Connecting with F5 Silverline® is optional, and is available for customers who have an active F5
Silverline DDoS Protection subscription.
To integrate the F5 Silverline Cloud
Platform with DDoS Hybrid Defender™ as a way to mitigate DDoS
attacks, you need to register DDoS Hybrid Defender with F5 Silverline.
If setting up
high availability, register with Silverline on the active device.
On the Main tab, click
On the menu bar, click Silverline.
In the Username field, type the user name for an active
Silverline DDoS Protection account. For example,
In the Password field, type the password for the
Silverline DDoS Protection account.
In the Service Address field, type the IP address or
fully qualified domain name used to connect to the Silverline DDoS Protection
Click Update to save the credentials.
DDoS Hybrid Defender sends a registration request to the F5 Silverline
Log in to the F5 Silverline customer portal
(https://portal.f5silverline.com) and specify DDoS
Hybrid Defender as an Approved Hybrid Signaling
DDoS Hybrid Defender is now integrated with the Silverline Cloud Platform.
When configuring the device or objects to protect, you will need to select the
Silverline check box to send information about DDoS attacks
to the Silverline Cloud Platform.