A10 ACOS 7.0.2 Security Guide
A10 ACOS 7.0.2 Security Guide
2
Application Delivery Controller Security
Guide
October, 2025
© 2025 A10 Networks, Inc. All rights reserved.
Information in this document is subject to change without notice.
PATENT PROTECTION
A10 Networks, Inc. products are protected by patents in the U.S. and elsewhere. The following website is provided
to satisfy the virtual patent marking provisions of various jurisdictions including the virtual patent marking
provisions of the America Invents Act. A10 Networks, Inc. products, including all Thunder Series products, are
protected by one or more of U.S. patents and patents pending listed at:
a10-virtual-patent-marking.
TRADEMARKS
A10 Networks, Inc. trademarks are listed at: a10-trademarks
CONFIDENTIALITY
This document contains confidential materials proprietary to A10 Networks, Inc. This document and information
and ideas herein may not be disclosed, copied, reproduced or distributed to anyone outside A10 Networks, Inc.
without prior written consent of A10 Networks, Inc.
DISCLAIMER
This document does not create any express or implied warranty about A10 Networks, Inc. or about its products or
services, including but not limited to fitness for a particular use and non-infringement. A10 Networks, Inc. has made
reasonable efforts to verify that the information contained herein is accurate, but A10 Networks, Inc. assumes no
responsibility for its use. All information is provided "as-is." The product specifications and features described in
this publication are based on the latest information available; however, specifications are subject to change without
notice, and certain features may not be available upon initial product release. Contact A10 Networks, Inc. for
current information regarding its products or services. A10 Networks, Inc. products and services are subject to A10
Networks, Inc. standard terms and conditions.
ENVIRONMENTAL CONSIDERATIONS
Some electronic components may possibly contain dangerous substances. For information on specific component
types, please contact the manufacturer of that component. Always consult local authorities for regulations
regarding proper disposal of electronic components in your area.
FURTHER INFORMATION
For additional information about A10 products, terms and conditions of delivery, and pricing, contact your nearest
A10 Networks, Inc. location, which can be found by visiting [Link].
Table of Contents
Getting Started 10
Application Access Management 11
Login Portal 11
Online Certificate Status Protocol (OCSP) 11
Authentication Relay 11
AAA Health Monitoring and Load Balancing 12
Online Certificate Status Protocol 12
DDoS Mitigation 12
Attack Detection and Prevention using ZBAR 13
Single CPU Attack Prevention 14
Policy-Based SLB 14
SYN Cookies 14
IP Limiting 15
ICMP Rate Limiting 15
Web Application Firewall 15
Slowloris Prevention 16
DNS Application Firewall 16
DNSSEC 16
SSL Insight 16
Geo-location-based VIP Access 17
IP Anomaly Filtering 18
Overview of IP Anomaly Filtering 19
IP Anomaly Filters 19
Frag 19
IP-option 19
Land-attack 20
Ping-of-death 20
TCP-no-flag 20
3
ACOS 7.0.2 Application Delivery Controller Security Guide
Contents
TCP-SYN-FIN 20
TCP-SYN-frag 20
Threshold 20
SOCKSTRESS_CHECK Session State 20
Implementation Notes 21
Configuring IP Anomaly Filtering 21
Using the GUI to Configure IP Anomaly Filtering 21
Using the CLI to Configure IP Anomaly Filtering 21
Displaying IP Anomaly Statistics 22
Using the GUI to Display IP Anomaly Statistics 22
Using the CLI to Display IP Anomaly Statistics 22
Policy-based SLB 24
Overview 25
Configuring a Black/White List 25
Configuration Details and Examples 26
Example Black/White List 27
Dynamic Black/White-list Client Entries 28
Connection Limit for Dynamic Entries 29
Aging of Dynamic Entries 29
Wildcard Address Support in PBSLB Policies Bound to Virtual Ports 29
Configuring System-wide PBSLB 30
Options for System-wide PBSLB Policies 30
Using the GUI to Configure System-wide PBSLB 30
Using the CLI to Configure System-wide PBSLB 31
Displaying and Clearing System-wide PBSLB Information 32
Configuring PBSLB for Individual Virtual Ports 32
Configuration Details 32
Using the GUI to Configure PBSLB for Individual Virtual Ports 33
Using the CLI to Configure PBSLB for Individual Virtual Ports 35
Configuration Example for Sockstress Attack Protection 36
4
ACOS 7.0.2 Application Delivery Controller Security Guide
Contents
SYN Cookies 40
Overview of SYN Cookies 41
SYN Flood Attacks 41
Identifying SYN Flood Attacks 41
ACOS SYN-cookie Protection 43
Dynamic SYN Cookies 43
SYN Cookie Buffering 44
SACK and MSS with Software-based SYN-cookies 44
SACK 45
MSS 45
Configuring SYN Cookies 45
Enabling SYN-cookie Support 45
Details 46
FTA Models 47
Non-FTA Models 47
Configuration with Target VIP and Client-side Router in Different Subnets 47
Modifying the Threshold for TCP Handshake Completion 48
Configuring SYN-cookie Buffering 49
Details 49
Using the GUI to Configure SYN-cookie Buffering 50
Using the CLI to Configure SYN-cookie Buffering 50
Viewing SYN-cookie Statistics 50
Using the GUI to View SYN-cookie Statistics 51
Using the CLI to View SYN-cookie Statistics 51
L4 SYN attack 51
L4 TCP Established 52
Examples 52
CLI Example 1: View Attack Prevention Statistics 52
CLI Example 2: View SYN Attack Counter 54
5
ACOS 7.0.2 Application Delivery Controller Security Guide
Contents
IP Limiting 56
Overview of IP Limiting 57
Understanding Class Lists 57
Class List Syntax 58
IP Address Matching 59
Example Class Lists 60
Configuring Class Lists 60
Using the GUI to Import a Class List 61
Using the GUI to Configure a Class List 61
Using the CLI to Import a Class List 61
Using the CLI to Configure a Class List 62
Understanding IP Limiting Rules 62
Parameters 63
Match IP Address 64
Request Limiting and Request-Rate Limiting in Class Lists 64
CLI Examples: Request Limiting and Request-rate Limiting Settings Are Used 65
Example 1: GLID Used in Policy Template and Bound to Virtual Port 65
Example 2: LID Used in Policy Template and Bound to Virtual Port 66
CLI Examples: Request Limiting and Request-rate Limiting Settings Are Not Used 67
Example 1: Policy Template Bound to Virtual Server Instead of Virtual Port 67
Example 2: System GLID 67
Example 3: System-wide Policy Template 67
Configuring Source IP Limiting 68
CLI Examples - Configuration 68
Configuring System-wide IP Limiting With a Single Class 69
Configuring System-wide IP Limiting With Multiple Classes 69
Configuring IP Limiting on a Virtual Server 70
6
ACOS 7.0.2 Application Delivery Controller Security Guide
Contents
7
ACOS 7.0.2 Application Delivery Controller Security Guide
Contents
8
ACOS 7.0.2 Application Delivery Controller Security Guide
Contents
9
Getting Started
ACOS provides a suite of security features that allow you to protect your customer
traffic:
10
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Getting Started
NOTE: For more information about AAM, see the Application Access
Management Guide.
Login Portal
Provides a sign-on interface. By using a request-reply exchange or using a Web-based
form, ACOS obtains the your credentials and uses a backend AAA server to verify
these credentials.
Authentication Relay
Offloads your AAA servers. ACOS contacts the backend AAA servers on behalf of the
clients, and after a server responds, ACOS caches the reply and uses this reply for
11
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Getting Started
NOTE: For more information about OSCP, see: Checking Client Certificates
Using OCSP in the SSL Configuration Guide and AAM with OCSP in the
Application Access Management Guide.
DDoS Mitigation
Distributed Denial of Service (DDoS) is a type of DoS attack where multiple systems
that are infected with a Trojan or malware are, in turn, used to target a particular
system. This process causes a denial of service. If a hacker (attacker) mounts an
attack from one host, this is classified as a DoS attack. In a DDoS attack, many
systems are used simultaneously to launch attacks against a remote system.
ACOS includes filters that check traffic for IP anomalies that can indicate a DDoS
attack.
NOTE: For more information about DDos Mitigation, see IP Anomaly Filtering.
12
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Getting Started
The captured packets for the bad sources can also be exported using the following
command,
export visibility pktcapture-file file
Additionally, the following show commands are added to view ZBAR information:
l show visibility zbar dest
l show visibility zbar dest bad-sources
13
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Getting Started
Policy-Based SLB
Policy-based SLB (PBSLB) allows you to “black list” or “white list” individual clients or
client subnets. Based on actions that you specify, ACOS will allow (white list) or drop
(black list) traffic from specific client hosts or subnets in the list.
NOTE: For more information about policy-based SLB, see Policy-based SLB.
SYN Cookies
SYN cookies provide protection against a common type of DDoS attack, the TCP SYN
flood attack. The attacker sends a high volume of TCP-SYN requests to the target
device, but the attacker does not reply to SYN-ACKs to complete the three-way
handshake for any of the sessions. The purpose of the attack is to consume the
target’s resources with half-open TCP sessions.
When SYN cookies are enabled, the ACOS device can continue to serve legitimate
clients during TCP SYN flood attacks, while preventing illegitimate traffic from
consuming system resources.
14
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Getting Started
NOTE: For more information about SYN cookies, see SYN Cookies.
IP Limiting
IP limiting provides a enhanced implementation of the source IP connection limiting
and connection-rate limiting feature that was available in earlier releases.
NOTE: For more information about ICMP rate limiting, see ICMP Rate Limiting.
NOTE: Fore more information about WAF, see the Web Application Firewall
Guide.
15
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Getting Started
Slowloris Prevention
In addition to the WAF, ACOS includes an HTTP security option that prevents
Slowloris attacks, in which the attacker attempts to consume resources on the target
system with incomplete HTTP request headers.
NOTE: For more information about Slowloris prevention, see HTTP Slowloris
Prevention.
NOTE: For more information about DAF, see DNS Application Firewall.
DNSSEC
ACOS supports DNS Security Extensions (DNSSEC). In Global Server Load Balancing
(GSLB) deployments, you can use DNSSEC with Hardware Module Security (HSM) to
dynamically secure DNS resource records for GSLB zones.
NOTE: The ACOS also supports DNS caching for DNSSEC, but DNSSEC support
for caching does not require GSLB.
SSL Insight
SSL Insight (SSLi) provides high-performance SSL decryption and re-encryption. When
used in conjunction with third-party traffic inspection devices, SSLi adds content-
16
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Getting Started
level security.
SSLi decrypts SSL-encrypted client traffic and sends the decrypted traffic to a third-
party traffic inspection device. Traffic that is permitted by the traffic inspection
device is re-encrypted by ACOS and forwarded to its destination.
NOTE: For more information about SSL Insight, see “SSL Insight” in the SSL
Configuration Guide.
ACOS determines a client’s location by looking up the client’s subnet in the geo-
location database that is used by Global Server Load Balancing (GSLB).
17
IP Anomaly Filtering
ACOS helps you detect and mitigate Distributed Denial of Service (DDoS) attacks.
One of the features, IP anomaly filtering, can protect against numerous types of
attacks.
18
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
IP Anomaly Filtering
IP Anomaly Filters
Users can enable the following IP anomaly filters. This section has the following sub-
sections:
Frag
Drops all IP fragments, which can be used to attack hosts that run IP stacks with
known vulnerabilities in their fragment reassembly code.
IP-option
Drops all packets with IP options.
19
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
IP Anomaly Filtering
Land-attack
Drops spoofed SYN packets that contain the same IP address as the source and
destination. These packets can be used to launch an “IP land attack”.
Ping-of-death
Drops all jumbo ICMP packets, which are also known as “ping of death” packets.
TCP-no-flag
Drops all TCP packets that have no TCP flags set.
TCP-SYN-FIN
Drops all TCP packets in which both the SYN and FIN flags are set.
TCP-SYN-frag
Drops incomplete (fragmented) TCP Syn packets, which can be used to launch TCP
Syn flood attacks.
Threshold
The threshold specifies the number of times the anomaly is allowed to occur in a
client’s connection requests.
If system-wide PBSLB is configured, ACOS applies the policy’s over-limit action to
clients that exceed the threshold. The range for the threshold value is 1-127
occurrences of the anomaly, and the default value is 10.
NOTE: The thresholds are not tracked by PBSLB policies that are bound to
individual virtual ports.
20
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
IP Anomaly Filtering
Implementation Notes
Consider the following implementation notes when you want to apply IP anomaly
filtering:
l DDoS mitigation feature is supported on the FTA-based Thunder series hardware
models, such as TH4440, TH7655S, etc.
l DDoS protection is software-based on other models.
l DDoS detection applies only to Layer 3, Layer 4, and Layer 7 traffic. However, Layer
4 and Layer 7 DDoS applies only to software releases that support Server Load
Balancing (SLB).
l All IP anomaly filters, except “IP-option”, apply to IPv4 and IPv6. The “IP-option”
filter applies only to IPv4.
l For Thunder 3030S, Thunder 1030S, and Thunder 930 models, all IP packets longer
than 32000 bytes are dropped. For other models, IP packets that are longer than
65535 bytes are dropped.
21
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
IP Anomaly Filtering
For example, the following command enables DDoS protection against ping-of-death
attacks:
Refer to the “ip anomaly-drop” command in the Network Configuration Guide for more
information about this command.
22
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
IP Anomaly Filtering
To clear all Layer 4 SLB statistics, including the IP anomaly counters, enter the clear
slb l4 command.
NOTE: For more information about these commands, see Command Line
Interface Reference Guide.
23
Policy-based SLB
This chapter helps you understand and configure policy-based SLB (PBSLB).
24
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Policy-based SLB
Overview
ACOS allows you to “black list” or “white list” individual clients or client subnets.
White list traffic is allowed, and black list traffic is dropped from specific client hosts
or subnets in the list.
For white list traffic, you can specify the service group to use. You also can specify
the action that will be taken (drop or reset) on new connections that exceed the
configured connection threshold for the client address.
Example
The user can configure ACOS to respond to DDoS attacks from a client by dropping
excessive connection attempts from the client.
You can apply PBSLB on a system-wide basis. If Server Load Balancing (SLB) is
supported, you also can apply PBSLB on individual virtual ports.
25
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Policy-based SLB
26
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Policy-based SLB
NOTE: The conn-limit is a coarse limit. The larger the number you specify, the
more coarse the limit.
Example
If you specify 100, the ACOS device limits the total connections to 100.
l As another example, if you specify 1000, the device limits the connections to a
maximum of 992 connections.
l If the number in the file is larger than the supported maximum limit value, the
parser uses the longest set of digits in the number that you enter that makes a
valid value.
Example
l If the file contains 32768, the parser uses 3276 as the value.
l As another example, if the file contains 111111, the parser will use 11111 as the
value.
27
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Policy-based SLB
The first row assigns a specific host to group 4. On the ACOS device, the drop action
is assigned to this group, which black lists the client.
The second row black lists an entire subnet by assigning it to the same group (4).
The third row sets the maximum number of concurrent connections for a specific
host to 20.
The fourth row assigns a specific host to group 2 and specifies a maximum of 20
concurrent connections.
NOTE: The ACOS device allows up to three parser errors when reading the file
but stops reading after the third parser error.
NOTE: If there is a static entry for the client’s host or subnet address, the
static entry is used instead.
28
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Policy-based SLB
In this example, the clients who do not match a static entry in the list are assigned to
group 1 and are limited to 20 concurrent connections.
The ACOS device supports up to 8 million dynamic client entries for system-wide
PBSLB. Once this limit is reached, the ACOS device no longer track connections or
anomaly counters for additional clients.
29
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Policy-based SLB
You can add a wildcard address ([Link]/0) to a black/white list that is used by a
virtual port’s PBSLB policy. The group ID and connection limit that are specified for
the wildcard address are applied to clients that do not match a static entry in the
list.
Consider the following limitations:
l The ACOS device does not create dynamic entries in the list.
l The connection limit applies collectively to all clients that do not have a static
entry in the list.
These options are not available in policies that are applied to individual ports.
30
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Policy-based SLB
31
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Policy-based SLB
To clear PBSLB information, use the clear pbslb system or clear pbslb client
commands.
Use the entry option with the clear pbslb client command to clear both
statistical counters and client entries; without this option, only the statistical
counters are cleared.
Configuration Details
You can configure PBSLB parameters for virtual ports by configuring the settings on
individual ports or by configuring a PBSLB policy template and binding the template
to individual virtual ports.
NOTE: This feature is supported only in software releases that support Server
Load Balancing (SLB).
These steps assume that the real servers, service groups, and virtual servers have
already been configured.
To configure PBSLB:
32
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Policy-based SLB
33
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Policy-based SLB
e. Click OK.
34
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Policy-based SLB
The following commands configure a PBSLB template and bind it to a virtual port:
35
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Policy-based SLB
PBSLB_VS1 80 sample-bwlist 2 0 0 0
4 0 0 0
PBSLB_VS2 80 sample-bwlist 2 0 0 0
4 0 0 0
The lockup period is set to 5 minutes, to continue enforcing the over-limit action for
5 minutes after the over-limit action is triggered. The timeout for dynamic
black/white list entries is set to 2 minutes.
This example uses the following black/white list:
[Link]/0 1 #20
36
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Policy-based SLB
The following command displays statistics for the system-wide PBSLB policy:
37
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Policy-based SLB
[Link] /32 D 1 20 6 0 5 0 6
6
[Link] /32 D 1 20 2 120 0 0 2
2
[Link] /32 D 1 20 5 120 0 0 5
5
[Link] /32 D 1 20 5 120 0 0 5
5
[Link] /32 D 1 20 5 120 0 0 5
5
[Link] /32 D 1 20 6 120 0 0 6
6
[Link] /32 D 1 20 6 0 5 0 6
6
[Link] /32 D 1 20 6 0 5 0 6
6
[Link] /32 D 1 20 6 0 5 0 6
6
[Link] /32 D 1 20 5 120 0 0 5
5
The Age column indicates how many seconds are left before a dynamic entry ages
out. For clients who are currently locked out of the system, the value in the Lockup
column indicates how many minutes the lockup will continue. For locked up clients,
the age value is 0 until the lockup expires. After the lockup expires, the age is set to
its full value. In this example, the lockup value is 120 seconds.
The following command displays detailed statistics for a specific black/white-list
client:
38
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Policy-based SLB
Out of sequence: 0
Zero window: 6
Bad content: 6
39
SYN Cookies
This chapter describes the SYN-cookie feature and how it helps protect ACOS
devices against disruptive SYN-based flood attacks.
40
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
SYN Cookies
41
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
SYN Cookies
The SYN-ACK Handshake (Legitimate Client) depicts a typical 3-way TCP handshake,
which includes a SYN request from the client, the SYN-ACK reply from the ACOS
device, and finally, an ACK from the client to the ACOS device.
Figure 1 : SYN-ACK Handshake (Legitimate Client)
However, SYN flood attacks (SYN-ACK Handshake (Hacker) ) can cripple a network by
sending multiple SYN requests to a network device. The device responds to these
SYN requests with SYN-ACKs and waits for responses from the client that never
arrive. These bogus requests create many “half-open” sessions, which wastes system
memory and other system resources. The state of being oversubscribed reduces the
device’s free resources, which prevents it from accepting requests from legitimate
clients.
Figure 2 : SYN-ACK Handshake (Hacker)
Enabling SYN cookies mitigates the damage caused by such DoS attacks by
preventing the attacks from consuming system resources.
TCP connections for which the ACOS device did not receive an ACK from the client is
identified as belonging to a SYN flood attack, and this information is displayed with
the counter in the output of the show command.
42
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
SYN Cookies
43
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
SYN Cookies
connections falls below this level, SYN cookies are disabled. You can specify 0-
2147483647 half-open connections.
By default, hardware-based SYN cookies are disabled. When the feature is enabled,
there are no default settings for the on- and off-threshold. If you omit the on-
threshold and off-threshold options, SYN cookies are enabled and are always on,
regardless of the number of half-open TCP connections on the ACOS device.
NOTE: It may take up to 10 milliseconds for the ACOS device to detect and
respond to crossover of either threshold.
44
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
SYN Cookies
SACK
The ACOS device includes the Sack-Permitted option in TCP SYN health check packets
sent to servers.
l If all of the up servers in the service group reply with a TCP SYN-ACK that contains
a SACK option, the ACOS device uses SACK with the software-based SYN-cookie
feature for all servers in the service group.
l If any of the up servers in the service group do not send a SACK option, the ACOS
device does not use SACK with the software-based SYN-cookie feature for any
servers in the service group.
MSS
The lowest MSS value that is supported by a server in the service group is the MSS
value that is used by the ACOS device for software-based SYN-cookies.
45
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
SYN Cookies
Non-FTA Models 47
Details
Depending on the Thunder or AX model, you can use hardware-based SYN cookies or
software-based SYN cookies:
l Hardware-based SYN cookies can be globally enabled and applied to all virtual
server ports that are configured on the device.
l Hardware-based SYN cookies are available on FTA devices. See the FTA Devices
section on the A10 Hardware Install Guides website for a list of FTA Thunder and
AX devices.
l Software-based SYN cookies can be enabled on individual virtual ports. This
version of the feature is available on all AX models.
NOTE: For more information, see Configuration with Target VIP and Client-
side Router in Different Subnets.
l Software-based SYN cookies are supported only in software releases that support
SLB.
46
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
SYN Cookies
FTA Models
To enable hardware-based SYN cookies on ACOS models that feature FTAs, use the
syn-cookie enable command at the global configuration level:.
The command in the following example enables dynamic-based SYN cookies when the
number of concurrent half-open TCP connections exceeds 50000 and disables SYN
cookies when the number falls below 30000:
Non-FTA Models
To enable software-based SYN cookies, use the syn-cookie command at the virtual-
port level. For example:
Hardware-based SYN Cookies – Target VIP and Client-Side Router in Different Subnets
is an example of this deployment.
Figure 3 : Hardware-based SYN Cookies – Target VIP and Client-Side Router in Different Subnets
47
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
SYN Cookies
The following commands configure hardware-based SYN cookies on the ACOS device:
ACOS(config)# slb virtual-server dummyvip [Link]
ACOS(config-slb vserver)# exit
ACOS(config)# syn-cookie
NOTE: If VRRP-A is configured, add both the target VIP and the dummy VIP to
the same VRID so these VIPs will fail over as a unit.
48
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
SYN Cookies
Details
When SYN cookies are enabled, 10 buffers are available to hold overflow packets
from each client session. When the system memory is occupied, the number of
buffers dedicated to each TCP connection is reduced. The reduction process occurs
gradually and is tied to system memory usage.
There are three different thresholds that can be configured on the ACOS device.
When these free system memory thresholds are breached, the number of buffers
that are allocated to each session (and the TCP window size) are reduced. This
reduction in the TCP window sized is an attempt to prevent the client from sending
data faster than the ACOS device can receive it.
The graduated buffers and window sizes appear below. By default, each TCP session
is allocated 10 buffers, and the TCP window size is set to 8K.
l If the first threshold is breached, the buffer is reduced to 4 buffers, and the TCP
window size is reduced to 4K.
l If the next memory threshold is breached, the buffer is reduced to 2 buffers, and
the TCP window size is reduced to 2K.
l If the final threshold is breached, the buffer is reduced to 1 buffer, and the TCP
window size is reduced to 1K.
These thresholds are based on system memory usage, and the values are
configurable.
Consider the following information:
l Each buffer size is approximately 1500 bytes.
The total number of buffers varies from one model to the next and is based on the
total memory per connection.
49
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
SYN Cookies
l If hardware-based SYN cookies are enabled, ACOS does not modify the TCP
window size.
NOTE: For more information, see the latest version of the Online Help for
additional information about the fields.
!
slb common
buff-thresh hw-buff num relieve-thresh num sys-buff-low num sys-buf-high
num
For additional information about changing the system memory thresholds, see the
buff-thresh command in the Command Line Interface Reference.
50
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
SYN Cookies
NOTE: For more information, see the latest version of the Online Help for
additional information about the fields.
The following fields in the output of the show slb l4 command allow you to view
TCP traffic in terms of legitimate traffic and attacks.
L4 SYN attack
Displays a running counter of the number of packets that the ACOS device considers
to be from a SYN flood attack. This assumption is based on the fact that the device
51
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
SYN Cookies
L4 TCP Established
Displays a running counter of TCP packets that the ACOS device considers to be from
legitimate clients. When SYN cookies are enabled, and a legitimate client sends a SYN
request, the ACOS device responds with a SYN ACK. If the ACOS device receives an
ACK, the packet is considered safe.
Examples
These fields are highlighted using these examples.
The following command displays SYN-cookie statistics across multiple time intervals:
52
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
SYN Cookies
The show slb attack-prevention fields displays the fields that appear in the CLI
output of the show slb attack-prevention command.
Limitations
l When running the show slb attack-prevention command on an FTA model, the
SYN attack field does not display output for the historical counters
(1s/5s/30s/1min/5min). Output is only provided for the Current column.
l This feature is supported for L3V private partitions in non-FTA models. If the show
slb attack-prevention command is run from an L3V network partitions on an FTA
model, the SYN attack counter displays zero for all columns.
53
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
SYN Cookies
54
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
SYN Cookies
The SYN cookie counter incremented? column indicates whether the SYN cookie
counter display will function correctly, based on the status of the other conditions
that are associated with this deployment.
1If hardware-based and software-based SYN cookies are enabled, only hardware-
based SYN cookies are used. “Irrelevant” means that hardware-based SYN cookies are
also enabled.
2“No” means that the SYN flood attack counters fail when hardware- and software-
based SYN cookies are enabled at the same time as L3V (private partitions). This is a
known limitation with this feature.
55
IP Limiting
56
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
IP Limiting
Overview of IP Limiting
IP limiting provides the following benefits:
l Configuration flexibility:
You can apply source IP limiting on a system-wide basis, on individual virtual servers,
or on individual virtual ports.
l Class lists:
You can configure different classes of clients, and apply a separate set of IP limits to
each class. You also can exempt specific clients from being limited.
NOTE: Layer 7 request limiting applies only to the HTTP, HTTPS, and fast-HTTP
virtual port types.
NOTE: Class lists can be configured only in the shared partition. A policy
template that is configured in a shared partition or in a private
partition can use a class list that is configured in the shared partition.
57
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
IP Limiting
The
58
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
IP Limiting
Class List Syntax Parameters provides a description of each portion of the format.
IP Address Matching
By default, the ACOS device matches the class-list entries based on the source IP
address of client traffic. Optionally, you can also match based on one of the following
items:
l Destination IP address:
Matches based on the IP address in a header in the HTTP request. You can specify the
header when you enable this option.
59
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
IP Limiting
[Link]/0 glid 1
60
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
IP Limiting
NOTE: If the class list contains at least 100 entries, you should use the
Store as a file option. A class list can be exported only if you use
this option.
6. Click Create.
61
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
IP Limiting
NOTE: See Class List Syntax for more information about the syntax.
62
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
IP Limiting
Parameters
IP limiting rules specify connection and request limits for clients.
Each IP limiting rule has the following parameters:
l Limit ID – Number from 1-31 that identifies the rule.
l Connection limit – Maximum number of concurrent connections that are allowed
for a client. You can specify 0-1048575. Connection limit 0 immediately locks down
matching clients, and there is no default value.
l Connection-rate limit – Maximum number of new connections that are allowed for
a client in the limit period. You can specify 1-2147483647 connections. The limit
period can be 100-6553500 milliseconds (ms), specified in increments of 100 ms.
There is no default.
l Request limit – Maximum number of concurrent Layer 7 requests that are allowed
for a client. You can specify 1-1048575, and there is no default.
l Request-rate limit – Maximum number of Layer 7 requests that are allowed for a
client in the limit period. You can specify 1-4294967295 connections. The limit
period can be 100-6553500 milliseconds (ms), specified in increments of 100 ms.
There is no default.
l Over-limit action – Action to take when a client exceeds at least one limit.
l The action can be one of the following:
l Drop – The ACOS device drops that traffic. If logging is enabled, the ACOS device
also generates a log message. This is the default action.
l Forward – The ACOS device forwards the traffic. If logging is enabled, the ACOS
device also generates a log message.
l Reset – For TCP, the ACOS device sends a TCP RST to the client. If logging is
enabled, the ACOS device also generates a log message.
l Lockout period – Number of minutes during which to apply the over-limit action
after the client exceeds a limit. The lockout period is activated when a client
exceeds a limit. The lockout period can be 1-1023 minutes, and there is no default.
l Logging – Generates log messages when clients exceed a limit. Logging is disabled
by default.
63
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
IP Limiting
When you enable logging, by default, a separate message is generated for each over-
limit occurrence. If you specify a logging period, the ACOS device keeps the repeated
messages for the specified period and sends a message at the end of the period for
all instances that occurred during this period.
The logging period can be 0-255 minutes. The default is 0, which means that there is
no wait period.
NOTE: For more information, see Request Limiting and Request-Rate Limiting
in Class Lists. The request limit and request-rate limit options apply
only to HTTP, fast-HTTP, and HTTPS virtual ports. The over-limit logging,
when used with the request-limit or request-rate-limit option, always
lists Ethernet port 1 as the interface.
Match IP Address
By default, the ACOS device matches class-list entries based on the source IP address
of client traffic. Optionally, you can also match based on one of the following
options:
l Destination IP address – Matches based on the destination IP address in packets
from clients.
l IP address in client packet header – Matches based on the IP address in the
specified header in packets from clients. If you do not specify a header name, this
option uses the IP address in the X-Forwarded-For header.
64
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
IP Limiting
ACOS(config)# class-list 2
ACOS(config-class list)# [Link]/32 glid 1023
ACOS(config-class list)# [Link]/24 lid 31
ACOS(config-class list)# exit
ACOS(config)# glid 1023
ACOS(config-glid:1023)# request-limit 10
ACOS(config-glid:1023)# request-rate-limit 2 per 100
ACOS(config-glid:1023)# over-limit-action reset log
ACOS(config-glid:1023)# exit
ACOS(config)# slb template policy global_policy
ACOS(config-policy)# class-list 2
65
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
IP Limiting
ACOS(config-policy-class-list:2)# exit
ACOS(config-policy)# exit
ACOS(config)# slb virtual-server vs-55 [Link]
ACOS(config-slb vserver)# vrid 1
ACOS(config-slb vserver)# port 80 http
ACOS(config-slb vserver-vport)# service-group vlan-80-grp
ACOS(config-slb vserver-vport)# template policy global_policy
ACOS(config)# class-list l2
ACOS(config-class list)# [Link]/32 lid 31
ACOS(config-class list)# exit
ACOS(config)# slb template policy poltemplate1
ACOS(config-policy)# class-list l2
ACOS(config-policy-class-list:l2)# exit
ACOS(config-policy)# class-list l3
ACOS(config-policy-class-list:l3)# lid 30
ACOS(config-policy-class-list:l3-lid:30)# request-limit 10
ACOS(config-policy-class-list:l3-lid:30)# request-rate-limit 2 per 100
ACOS(config-policy-class-list:l3-lid:30)# exit
ACOS(config-policy-class-list:l3)# exit
ACOS(config-policy)# exit
ACOS(config)# slb virtual-server vs-55 [Link]
ACOS(config-slb vserver)# vrid 1
ACOS(config-slb vserver)# port 80 http
ACOS(config-slb vserver-vport)# service-group vlan-80-grp
ACOS(config-slb vserver-vport)# template policy poltemplate1
66
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
IP Limiting
67
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
IP Limiting
Clients must comply with all IP limiting rules that are applicable to the client. For
example, if you configure system-wide IP limiting and also configure IP limiting on a
virtual server, clients must comply with the system-wide IP limits and with the IP
limits that are applied to the individual virtual server accessed by the client.
68
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
IP Limiting
ACOS(config)# glid 1
ACOS(config-glid:1)# conn-rate-limit 10000 per 1
ACOS(config-glid:1)# conn-limit 1000000
ACOS(config-glid:1)# over-limit-action forward log
ACOS(config-glid:1)# exit
ACOS(config)# system glid 1
The following commands configure class list “global”, which matches on all clients
and uses IP limiting rule 1:
The following command imports the class list that are used by the policy:
69
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
IP Limiting
The following command imports the class list that is used by the policy:
70
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
IP Limiting
The following command imports the class list that is used by the policy:
71
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
IP Limiting
72
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
IP Limiting
expires, the host entry is removed form the class list, and the connection limit no
longer applies to the client.
Host [Link] is not allowed to establish a connection during the first 10
minutes after that host entry is created. Once the age expires, the client is no longer
locked down.
Viewing Class-Lists
Use the show class-list command to view information about your class list
configuration.
NOTE: For information, see “show class-list” in the Command Line Interface
Reference.
NOTE: For information, see “show glid” in the Command Line Interface
Reference.
73
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
IP Limiting
NOTE: For information, see “show pbslb” in the Command Line Interface
Reference.
74
ICMP Rate Limiting
75
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
ICMP Rate Limiting
1Subsequent references use the term “ICMP rate limiting”. Unless otherwise
specified, this term also applies to ICMPv6 rate limiting.
76
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
ICMP Rate Limiting
When ICMP traffic is locked up, all ICMP packets are dropped until the lockup
expires. The maximum rate can be 1-65535 packets per second.
l Lockup time – The lockup time is the number of seconds for which the ACOS device
drops all ICMP traffic, after the maximum rate is exceeded.
The lockup time can be 1-16383 seconds.
NOTE: Specifying a maximum rate (lockup rate) and lockup time is optional. If
you do not specify them, lockup does not occur. Log messages are
generated only if the lockup option is used and lockup occurs.
Otherwise, the ICMP rate-limiting counters are still incremented but log
messages are not generated.
NOTE: The maximum rate must be larger than the normal rate.
NOTE: For descriptions of the parameters, see ICMP Rate Limiting Parameters.
77
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
ICMP Rate Limiting
NOTE: This option applies only to software releases that support SLB.
NOTE: For descriptions of the parameters, see ICMP Rate Limiting Parameters.
You can enter the icmp-rate-limit command at any of the following configuration
levels:
l Global configuration level
l Configuration level for a physical or virtual Ethernet interface
l Configuration level for a virtual server template
NOTE: For descriptions of the parameters, see ICMP Rate Limiting Parameters.
78
HTTP Slowloris Prevention
79
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
HTTP Slowloris Prevention
Details
The ACOS includes an HTTP template option that specifies the maximum number of
seconds allowed for all parts of a request header to be received. If the entire request
header is not received within the specified amount of time, ACOS terminates the
connection.
This option provides security against attacks such as Slowloris attacks, which
attempt to consume resources on the target system by sending HTTP requests in
multiple increments, and at a slow rate. The intent of this type of attack is to cause
the target system to consume its buffer resources with the partially completed
requests.
NOTE: The request-header wait time can bet set to 1-31 seconds. The default is
7 seconds.
80
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
HTTP Slowloris Prevention
NOTE: For more HTTP security options, see the Web Application Firewall
Guide.
81
DNS Application Firewall
82
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Application Firewall
83
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Application Firewall
For a DNS client request to pass the sanity check, all of the following conditions must
be met:
l [Link] == 0 (first bit in flags)
l [Link] <=5 (bits 2 to 5 in flags)
l [Link] == 0 (last 4 bits in flags)
l qdcount > 0 (questions in DNS header)
For a server response (if applicable) to pass the sanity check, all of the following
conditions must be met:
l [Link] == 1 (first bit in flags)
l [Link] <=5
l [Link] == 0
l qdcount > 0
l ancount > 0 (Answer count)
84
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Application Firewall
1. Create a DNS template and specify the DNS security action in the template.
2. Bind the DNS template to the DNS virtual port.
The following commands configure the real server and service group:
ACOS(config)# slb server dns-sec1 [Link]
ACOS(config-real server)# port 53 udp
ACOS(config-real server-node port)# exit
ACOS(config-real server)# exit
ACOS(config)# slb service-group dns-sec-grp udp
ACOS(config-slb svc group)# member dns-sec1 53
ACOS(config-slb svc group-member:53)# exit
ACOS(config-slb svc group)# exit
The following commands bind the service group and DNS template to the DNS virtual
port on a virtual server:
ACOS(config)# slb virtual-server dnsvip1 [Link]
ACOS(config-slb vserver)# port 53 udp
ACOS(config-slb vserver-vport)# service-group dns-sec-grp
ACOS(config-slb vserver-vport)# template dns dns-sec
Since the drop action is specified, malformed DNS queries sent to the virtual DNS
server are dropped by the ACOS device.
85
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Application Firewall
86
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Application Firewall
Workflow
The following workflow outlines the steps taken by a DNS Firewall utilizing RPZ to
inspect, evaluate, and respond to DNS queries:
1. When a user attempts to access a domain, the DNS query is intercepted by the
DNS firewall.
2. The DNS firewall processes the query and evaluates it against the RPZ rules
defined in the RPZ file.
3. Based on the matched RPZ rule, the DNS firewall applies the appropriate action
(block, redirect, etc.). The action can either be an error reply, a walled garden IP,
or dropped packets.
4. The modified or blocked response is sent back to the user.
Figure 4 : DNS RPZ Firewall
87
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Application Firewall
88
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Application Firewall
89
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Application Firewall
90
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Application Firewall
;SOA Record
@ IN SOA localhost. [Link] (
91
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Application Firewall
; NXDOMAIN action (domain does not exist) for query name [Link]
[Link] IN CNAME .
92
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Application Firewall
ACOS parses and processes both policies, resulting in the same action i.e., in both
cases, when a DNS query with the domain name [Link] and A record
type is received, ACOS will respond with the IP address [Link].
However, as mentioned earlier, ACOS only recognizes and parses RR types listed in
Table 4 and TYPE<num>. Therefore, for other RR types, you must specify TYPE<num> in
the RPZ file. For example, HTTPS record are not supported, therefore, to process
these records, you need to specify TYPE65.
Consider the following two policies:
[Link] IN TYPE65 .
[Link] IN HTTPS .
93
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Application Firewall
The first policy will be parsed and processed by ACOS, resulting in an NXDOMAIN
response. However, the second policy will result in a parsing error (since HTTPS RR
type is not supported), and all valid/invalid policies below it will be ignored.
CLI Configuration
ACOS can import customized RPZ and support all its policies. ACOS applies the RPZ
policy when DNS transactions occur at the virtual port with the DNS template.
l To configure a DNS Firewall using RPZ on your system, perform the following steps:
1. Import a customized RPZ file.
To import the RPZ file, use the import or import-periodic command in the
following manner:
ACOS(config)# import rpz [Link] use-mgmt-port
scp://root@[Link]/root/[Link]
Additionally, to ensure a secure transaction, you can import an RPZ file using
DNS zone transfer with Transaction Signature (TSIG) as shown below:
ACOS(config)# import rpz [Link] zone-transfer use-mgmt-port
axfr://[Link].+157+[Link]@[Link]/root/[Link]
In the above example, [Link].+157+[Link] is the TSIG public key file that
can be imported using the import tsig command.
2. Bind the RPZ to the DNS template.
ACOS(config)# slb template dns dns_template1
ACOS(config-dns)# rpz 1 [Link]
ACOS(config-dns-rpz)# logging enable
ACOS(config-dns-rpz-logging:enable)# rpz-action drop
ACOS(config-dns-rpz-logging:enable)# rpz-action tcp-only
NOTE: You cannot bind more than 8 RPZ files on the same DNS template.
94
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Application Firewall
l To relieve RPZ from the DNS template, use the following command:
ACOS(config-dns)# no rpz [Link]
$TTL 1H
$ORIGIN rpz.
@ IN SOA localhost. [Link] (
2015103102
1h
95
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Application Firewall
15m
30d
2h )
NS localhost.
; DROP action
[Link].[Link]-client-ip IN CNAME rpz-drop. ;
Client ip
[Link].[Link]-ip IN CNAME rpz-drop. ;
Response IP
[Link] IN CNAME rpz-drop. ; QNAME
[Link]-nsdname IN CNAME rpz-drop. ;
NSDNAME
[Link].[Link]-nsip IN CNAME rpz-drop. ; NSIP
; TCP-Only action
*.[Link] IN CNAME rpz-tcp-only.
; PASSTHRU action
[Link] IN CNAME rpz-passthru.
; NXDOMAIN action
[Link] IN CNAME .
; NODATA action
[Link] IN CNAME *.
; IPv6 example
[Link]-ip IN CNAME rpz-drop.
[Link]-ip IN CNAME rpz-drop.
96
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Application Firewall
l To view the DNS RPZ statistics per service counter, use the following command:
ACOS(config)# show slb virtual-server v1 53 <dns-udp/dns-tcp>
application-statistics
97
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Application Firewall
For more information on the global DNS cache configuration, see Application Delivery
and Server Load Balancing Guide.
98
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Application Firewall
1. Configure a case-insensitive string type class-list that contains the legal TLD.
ACOS(config)# class-list TLD-list string-case-insensitive
ACOS(config-class-list)# str com
2. Configure the SLB DNS template to enable TLD filtering and logging.
ACOS(config)# slb template dns d1
ACOS(config-dns)# tld-filter-white-list TLD-list
ACOS(config-dns)# tld-filter-log-enable
Logs
99
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Application Firewall
ACOS generates SYSLOG such as the following when the DNS query is dropped due to
TLD filtering:
486707686847545345#tcp [Link] 1 [Link] 1 Type=query QueryId=1345
Opcode=QUERY HeaderFlag=RD QDCount=0 ANCount=0 NSCount=0 ARCount=0
dhost=[Link] QueryType=A QueryClass=IN TLD Filter Drop
ACOS generates CEF log such as the following when the DNS query is dropped due to
TLD filtering:
486707686847545345#proto=tcp src=[Link] spt=1 dst=[Link] dpt=1 cs1=query
cs1Label=Query cn1=1345 cn1Label=Query ID cs2=QUERY cs2Label=Opcode cs3=RD
cs3Label=Header Flag cn2=0 cn2Label=Question Count cn3=0 cn3Label=Answer
Record Count cn4=0 cn4Label=Authority Record Count cn5=0
cn5Label=Additional Record Count dhost=[Link] cs4=A
cs4Label=Query Type cs5=IN cs5Label=Query Class reason=TLD Filter Drop
CLI Configuration
100
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Application Firewall
The SLB template can then be bound to the DNS virtual port.
Option description:
l action { drop | ignore } – Configure the action to drop or forward the DNS
requests when the FQDN label length exceeds the configured threshold limit.
l drop-log-enable - Enable logging when the DNS request is dropped.
l fqdn-label-length - Set the maximum length for an individual label in an FQDN.
While checking the label lengths, you can also use the suffix parameter to specify
the number of trailing labels to be ignored in an FQDN. For example, if an FQDN
has 5 labels and the suffix is set to 2, the length of the first 3 labels will be checked
and the last two labels will be ignored.
Example:
The following example demonstrates the usage of the label-length-filter
command:
ACOS(config)# slb template dns <template_name>
ACOS(config-dns)# label-length-filter
ACOS(config-dns-label-count-filter)# drop-log-enable
ACOS(config-dns-label-count-filter)# action drop
ACOS(config-dns-label-count-filter)# fqdn-label-length 40 suffix 3
ACOS(config-dns-label-count-filter)# fqdn-label-length 43
The above configuration has two rules to check the FQDN label length. As per the
first rule, after ignoring the last 3 labels, if the length of other labels is greater than
101
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Application Firewall
40, the DNS request be dropped. As per the second rule, if the length of any FQDN
label is greater than 43, the DNS request will be dropped.
Generated Logs
Below are examples of logs generated when a DNS request is dropped by the
FQDN label-length filter with the drop-log-enable command configured:
Syslog:
May 6 13:24:28 vThunder a10logd: [ACOS]<6> UDP [Link] 49179
[Link] 53 Type=Query QueryId=44485 Opcode=Query HeaderFlag=RD|AD
QDCount=1 ANCount=0 NSCount=0 ARCount=1 dhost=[Link] QueryType=A
QueryClass=IN Label Length Filter Drop
CEF example:
May 6 13:24:28 vThunder CEF:0|A10|CFW|6.0.4-d-
484066f|486707618128068611|Log DNS Query Drop for FQDN label length
Filter|2|proto=UDP src=[Link] spt=49179 dst=[Link] dpt=53
cs1=Query cs1Label=Query cn1=44485 cn1Label=Query ID cs2=Query
cs2Label=Opcode cs3=RD|AD cs3Label=Header Flag cn2=1 cn2Label=Question
Count cn3=0 cn3Label=Answer Record Count cn4=0 cn4Label=Authority Record
Count cn5=1 cn5Label=Additional Record Count dhost=[Link] cs4=A
cs4Label=Query Type cs5=IN cs5Label=Query Class reason= Label Length Filter
Drop
The SLB template can then be bound to the DNS virtual port.
Option description:
102
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Application Firewall
l action { drop | ignore } – Configure the action to drop or forward the DNS
requests when the FQDN label count exceeds the configured threshold limit.
l drop-log-enable - Enable logging when the DNS request is dropped.
l max-fqdn-label-count - Set the maximum number of FQDN labels allowed per
FQDN. The configured action is taken when this threshold is breached. For
example, if the count is set to 5, DNS requests with FQDNs having 5 or more labels
are dropped.
l min-fqdn-label-count - Set the minimum number of FQDN labels allowed per
FQDN. The configured action is taken if the number of labels is less than this value.
For example, if the count is set to 2, DNS requests with FQDNs having single labels
are dropped.
Example:
The following example demonstrate the usage of the label-count-filter command:
ACOS(config)# slb template dns temp
ACOS(config-dns)# label-count-filter
ACOS(config-dns-label-count-filter)# drop-log-enable
ACOS(config-dns-label-count-filter)# action drop
ACOS(config-dns-label-count-filter)# min-fqdn-label-count 2
ACOS(config-dns-label-count-filter)# max-fqdn-label-count 6
As per this configuration, DNS requests with FQDNs having single labels or more than
6 labels will be dropped.
Generated Logs
Below are examples of logs generated when a DNS request is dropped by the
FQDN label-count filter with the drop-log-enable command configured:
Syslog example:
May 3 17:53:05 vThunder a10logd: [ACOS]<6> UDP [Link] 54315
[Link] 53 Type=Query QueryId=41043 Opcode=Query HeaderFlag=RD|AD
QDCount=1 ANCount=0 NSCount=0 ARCount=1 dhost=[Link] QueryType=A
QueryClass=IN Label Count Filter Drop
103
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Application Firewall
104
DNS Response Rate Limiting
Overview
For some ADC deployments, it may be difficult to control the rate of DNS responses
from the DNS servers to external hosts. This vulnerability could cause your network
resources to be used in DNS reflection, DNS amplification, or DNS Water Torture
attacks.
To address this vulnerability, ACOS offers support for DNS Response Rate Limiting
(RRL) to mitigate the risk associated with such attacks. With DNS RRL, ACOS can
effectively control the rate of DNS server responses associated with the DNS
requests flagged as potentially malicious.
105
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Response Rate Limiting
replying to the real source of the threat. When the hacker scales up the attack by
employing botnets, the replies from the DNS servers can use up all the resources on
the target’s network, preventing legitimate traffic from getting through.
Using DNS RRL, ACOS can prevent the reflection attacks by restricting the number of
identical queries per class-list.
The NXDOMAIN response rate limit is enabled only when the filter-response-rate
limit is exceeded.
Once the source is flagged as potentially malicious, then ACOS can initiate protective
measures.
106
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Response Rate Limiting
BIND software tracks all DNS queries by placing them into one large table. However,
to allocate system resources more efficiently, the ACOS implementation of DNS RRL
uses a two-tiered system with two tables.
l filter table - This table processes all the normal DNS queries. When the number of
requests from a source address/FQDN pair exceeds the filter-table-response rate,
this source address/FQDN pair is added and tracked in the rate-limiting entry
table.
o Size depends on the platform:
On platforms with less than 7 CPUs, the size is 4096 bytes.
On platforms >= 7 CPUs, the size is 12288 bytes.
o Refill cycle:
ACOS 4.x release refills every 2 seconds
ACOS 5.x release refills every 1 second.
l rate-limiting entry table - This table tracks the DNS requests that are potentially
malicious or abnormal, which are sent from offenders and must be closely
monitored. Only a small subset of DNS queries is placed into this table of potential
abusers. It uses approximately 100 bytes for each DNS query. After all the entries
in the table are used up, all other traffic is placed into an overflow bucket where
the source IP + FQDN is no longer tracked.
The rate-limiting table allocates a credit rate to each source address/FQDN pair
entry (for example, a credit of up to 10 requests per second), which can be used
up. Any DNS queries exceeding their credit rate are then rate-limited, and ACOS
drops the traffic beyond the threshold.
107
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Response Rate Limiting
NOTE: ACOS does not apply rate limits to the malicious queries themselves
but only to the responses from the DNS server to the victim. DNS RRL is
not supported on service partitions.
While the RRL feature is typically used only by authoritative name servers to mitigate
the impact of DDoS amplification attacks, it can also be used by recursive servers
(resolvers) as a method of load limiting. However, disabling or restricting recursion in
the name server is highly recommended.
If a resolver is required, it should only be available as a non-authoritative server that
can only be accessed by the intended clients, preferably those with IP addresses that
cannot be spoofed as, for example, private networks.
NOTE: DNS RRL feature works when the template is bound to virtual port type
dns-udp only.
The following options are available under slb template dns > response-rate-
limiting:
l TC-rate - This option configures the rate at which the DNS server responds with a
truncated (TC) response. Every nth rate limited request will get a TC bit response
and force the requestor to use TCP.
The value can be set from 2 - 10. For example, if the TC-Rate is set to 3, one of
every 3 rate-limited (dropped) queries will receive a truncated response.
l action - This option configures the action to be taken if the DNS response rate limit
exceeds. The following options can be configured:
o log-only - Enables “log only” behavior for rate limiting. ACOS will behave as if
the queries are being rate-limited. Logs will be sent out, and counters will
increment, but this is done without actually applying rate limits to DNS
responses. Enabling this option also requires selecting the “enable-log”
configuration.
108
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Response Rate Limiting
l nxdomain response rate - This option configures the maximum allowed rate of
non-existent domain (NXDOMAIN) responses. The responses that exceed this value
are dropped without considering truncated responses or partial allowance through
slip rates.
This option can be configured at:
o SLB template per virtual port level where the value can range from 1 - 1000
responses per configured window.
o DNS RRL Class-List LID template level where the value can range from 1 -
16000000 responses per configured window.
The default value is set to 5 per second.
109
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Response Rate Limiting
NOTE: TC-rate and slip-rate are not supported for NXDOMAIN RRL.
l match subnet (IPv4 or IPv6) - This option configures the IPv4 or IPv6 prefix length
to indicate the size of the subnet in which the incoming queries are grouped.
l slip rate - This option allows a certain percentage of valid DNS queries to pass
through, even during an attack. Every nth response that is rate-limited will instead
be let through.
The value can be set from 2 - 10 and should approximate the retry count for
regular queries.
l source IP only - This option allows response rate limiting only based on source IP
instead of FQDN.
l window - This option configures the rate-limiting-window. It is the interval over
which rates are measured for response-rate and slip-rate. If the same DNS
mapping is requested too many times, similar queries from that client are dropped
for the rest of the window’s interval.
The default value is 1 second, and the value can be from 1 - 60 seconds.
110
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Response Rate Limiting
Configuration Example
The following topics are covered:
CLI Configuration 111
GUI Configuration 113
Show Commands 114
CLI Configuration
Example 1
To configure DNS RRL using SLB Template DNS, use the following commands:
1. Enable DNS RRL:
ACOS(config)# slb common
ACOS(config-common)# dns-response-rate-limiting
ACOS(config-common-dns-response-rate-limi...)# max-table-entries 20000
ACOS(config-common-dns-response-rate-limi...)# exit
111
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Response Rate Limiting
5. Configure a virtual server and a port on the ACOS device and associate them with
the proper service group:
ACOS(config)# slb virtual-server VS [Link]
ACOS(config-slb vserver)# port 53 dns-udp
ACOS(config-slb vserver-vport)# template dns DNSRRL
ACOS(config-slb vserver-vport)# service-group SG
ACOS(config-slb vserver-vport)# exit
Example 2
To configure NXDOMAIN Response Rate Limiting, use the following commands:
1. Enable DNS Response Rate Limiting and set the source entry age:
ACOS(config)# slb common
ACOS(config-common)# dns-response-rate-limiting
ACOS(config-common-dns-response-rate-limi...)# source-entry-age 5
ACOS(config-common-dns-response-rate-limi...)# exit
ACOS(config-common)# exit
3. Configure NXDOMAIN Response Rate Limiting at SLB template per virtual port:
ACOS(config)# slb template dns nx
ACOS(config-dns-response-rate-limiting)# response-rate-limiting
ACOS(config-dns-response-rate-limiting)# nx-response-rate 1
4. Configure NXDOMAIN Response Rate Limiting at DNS RRL Class-List LID template
level:
ACOS(config-dns-response-rate-limiting)# rrl-class-list a10
ACOS(config-dns-response-rate-limiting-rr...)# lid 1
ACOS(config-dns-response-rate-limiting-rr...)# nx-response-rate 3
ACOS(config-dns-response-rate-limiting-rr...)# exit
ACOS(config-dns-response-rate-limiting)# exit
112
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Response Rate Limiting
7. Configure a virtual server and a virtual port on the ACOS device and associate
them with the proper service group:
ACOS(config)# slb virtual-server vip [Link]
ACOS(config-slb vserver)# port 53 dns-udp
ACOS(config-slb vserver-vport)# template dns DNSRRL
ACOS(config-slb vserver-vport)# service-group SG
ACOS(config-slb vserver-vport)# exit
GUI Configuration
The DNS RRL feature helps prevent network equipment (DNS authoritative servers)
from becoming unwanted participants in a DNS reflection or DNS amplification
attack.
To configure DNS Response Rate Limiting using SLB Template DNS:
1. Navigate to the ADC > Templates > L7 Protocols menu.
2. Click Create, and select DNS from the drop-down menu.
3. Select the DNS Response Rate Limiting checkbox.
4. You can configure the options from this page to enable DNS Response Rate
Limiting (RRL).
5. Click OK to save your changes.
To set limits around the amount of memory consumed during a DNS reflection attack:
113
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Response Rate Limiting
Show Commands
This section describes the various show commands:
l To view normal DNS traffic (without RRL settings), use the following command:
ACOS(config)# show dns statistics
114
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Response Rate Limiting
115
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Response Rate Limiting
l To view the DNS RRL statistics of a virtual server, use the following command:
ACOS(config)# show slb virtual-server v1 53 dns-tcp application-
statistics
Total DNS Query: 0
Total Malformed Query: 0
116
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNS Response Rate Limiting
l To view the counters for NXDOMAIN response rate limiting, use the following
command:
ACOS(config-dns-response-rate-limiting)# show slb virtual-server vip 53
dns-udp application-statistics
...
...
RRL NXDOMAIN Exceed (Server-Side): 6
RRL QPS Drop / Log (Client-Side): 0
RRL NXDOMAIN Drop/ Log (Client-Side): 1
...
...
Response Rate Limiting Total Allowed: 0
Response Rate Limiting Total Dropped: 0
117
DNSSEC Support
118
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNSSEC Support
Details
An ACOS device that is configured as a Global Server Load Balancing (GSLB) controller
can act as an authoritative DNS server for a domain zone. As the authoritative DNS
server for the zone, the ACOS device sends records in response to requests from DNS
clients. The ACOS device supports the ability to respond to client requests for the
following types of records:
l A
l AAAA
l CNAME
l NS
l MX
l PTR
l SRV
l TXT
If you place the ACOS device in the DNS infrastructure, the device is exposed to
potential online attacks. When DNS was originally designed, there were no
mechanisms to ensure the DNS infrastructure would remain secure.
In an unsecured DNS environment, the client’s DNS resolver has no way to assess the
validity of the address it receives for a particular domain name, so the client’s DNS
resolver cannot tell whether an address received for a particular domain is from the
legitimate owner of that domain.
119
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNSSEC Support
120
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNSSEC Support
121
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNSSEC Support
2. The Caching DNS server has a list of IP address- to- domain mappings, but
the list is not comprehensive, and unfortunately, the Caching DNS server
does not have the required IP address.
It acts as a proxy for the client and makes a recursive query to the Root DNS
Server, which is located at the top of the DNS hierarchy.
3. The Root DNS Server does not have the requested IP address.
4. In an attempt to point the Caching DNS server in the right direction, it
responds to the request with a Name Server (NS) record, which contains the
IP of the Top Level Domain (TLD) server for the “.org ” domain.
5. The Caching DNS server now has the IP address for the name server that manages
the “.org ” domain, so it sends an address request on behalf of the client to the
TLD DNS server for the “.org ” domain.
6. The TLD Server does not have the requested IP address.
7. The TLD server points the Caching DNS server in the right direction by providing
an NS record that contains the IP address for the next name server in the DNS
hierarchy, which is the authoritative DNS server for the [Link] subdomain.
8. The Caching DNS server has the IP address that is needed to reach the
authoritative DNS server for the [Link] domain, so the server sends a
request for [Link] to this authoritative DNS server.
9. The authoritative DNS server does not have the requested information, but it can
get the Caching DNS server one step closer to its destination by providing the NS
record for the authoritative DNS server for the [Link] domain.
10. The Caching DNS Server sends a request to the authoritative DNS server for the
[Link] domain.
11. The ACOS device, which is the authoritative DNS server for [Link],
has the IP address that the client needs.
12. The ACOS device sends the requested IP address to the Caching DNS server.
13. The Caching DNS server sends the IP address that is provided by the ACOS device
to the DNS resolver in the client’s browser.
The client now has the IP address needed to reach the server in the zone1
subdomain.
122
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNSSEC Support
As the first step in securing a zone with DNSSEC, all the records with the same
name/type/class are grouped into a resource record set (RRset). For example, in case
of three AAAA records in the zone at the same label (i.e. [Link]), the
records are all grouped into a single AAAA RRset. This entire RRset gets digitally
signed, as against individual DNS records.
The digital signature is created by applying a hash function to the DNS record to
reduce its file size, an encryption algorithm is applied to the hash value (using the
private key). The encrypted hash value appears as the digital signature stored in
RRSIG record. It appears at the bottom of the record being signed.
While the DNS Packet Flow without DNSSEC shows how basic DNS works without
DNSSEC, the Figure 6 shows how the DNS lookup process works with DNSSEC.
123
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNSSEC Support
The recursive lookup process remains largely unchanged, with the higher-level DNS
servers pointing to lower level servers in the DNS hierarchy to move the request
closer to the authoritative server for the desired domain.
However, when DNSSEC is added, the additional records such as DS, RRSIG, and
DNSKE are used to sign and authenticate the communications from the DNS servers.
This step proves to the client that each of the name servers in the “chain of trust”
are authoritative for their respective domains. DNS resolver sets the "DO" (DNSSEC
Ok) flag in its queries to indicate that it supports DNSSEC and servers that support
DNSSEC should consider this flag.
124
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNSSEC Support
The Figure 6 shows the resolution process for an address query from the DNS
resolver on a client for the IP address of [Link].
1. The DNS resolver on the client sends an address query for the IP address of a
host under [Link].
2. The Caching DNS server, which does not have the address, forwards the request
to the root server.
3. The root server redirects the Caching DNS server to the TLD DNS server for the
.org domain.
125
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNSSEC Support
126
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNSSEC Support
16. The ACOS device sends its DNSKEY record, with an RRSIG record that was used to
sign the DNSKEY record.
17. The RRSIG record contains the private key.
18. To continue assembling the chain of trust, the Caching DNS server asks the
Authoritative DNS server for [Link] for its DNSKEY record.
19. The Authoritative DNS server for [Link] sends its DNSKEY record with an
RRSIG record (with the private key) that was used to sign the DNSKEY record.
20. The Caching DNS server asks the TLD server for .org for its DNSKEY record.
21. The TLD server sends its DNSKEY record with an RRSIG record that was used to
sign the DNSKEY record.
22. The Caching DNS server now has all the private/public key pairs and has validated
all of the links in the chain of trust.
The Caching DNS server can now send the trusted response to the DNS resolver on
the client.
127
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNSSEC Support
will not be sent if it fails the validation. DNSSEC validation can occur only if the CD
bit is clear (CD=0), that is, Checking Enabled.
For details on the DNSSEC validation workflow, see the Application Delivery
Controller Guide.
128
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNSSEC Support
The DNSSEC Chain of Trust shows the Authoritative DNS Server for the
[Link] domain at the bottom left, and the Root DNS Server is located at
the upper right.
Starting from the lower left, the Authoritative DNS Server for the [Link]
domain, has a DNS key record (DNSKEY). This DNSKEY record contains the public Zone
129
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNSSEC Support
Signing Key (ZSK) for zone1. The ZSK is used to sign other record types, such as A
records, for the zone. The DNSKEY record is signed by the Key Signing Key (KSK),
which also belongs to this zone.
The Start of Authority (SOA) record indicates that this server is the Authoritative
DNS Server for zone1. The A record provides the IP address for [Link].
The next level up in the DNS hierarchy corresponds to the next “label” in the
[Link] domain, and it has a record called the Delegation Signer (DS). The DS
record contains a hash, or message digest, of the public Key Signing Key (KSK), which
belongs to the Authoritative DNS Server for the node below, [Link].
The DNS resolver (or the Caching DNS Server) can compare the hash value for any of
the nodes in the Chain of Trust, and the values should match. If the hash values in a
DS record cannot be recreated from the DNSKEY record, packet that contains the key
record may have been tampered with, cannot be trusted, and should be discarded.
However, if the hash value is correct, this indicates that the Chain of Trust is
unbroken and that the DNSKEY record for the Authoritative DNS Server that is
associated with the [Link] domain is properly linked to the DS record
above.
In turn, the DNSKEY record for the Authoritative DNS Server associated with the
[Link] domain is properly linked to the DS record above. This process of
DNSKEY records being linked with the DS record of the node above continues all the
way to the Root DNS Server.
The client’s DNS resolver knows that the Root DNS Server is legitimate due to the
presence of a “trust anchor”. This trust anchor, which consists of information for the
Root DNS Server, is included in the resolver software that is installed on the client.
This minimizes the chance that a client could access a corrupt root DNS server.
Because of this anchor, the client knows that the Root DNS Server can be trusted,
and the client can infer that the other nodes in the Chain of Trust can also be
trusted. The hash values match all the way down the line, which is an indication that
the Chain of Trust is intact, and that the client’s DNS resolver can trust the
Authoritative DNS Server for [Link]. The Server is located at the bottom
of the Chain of Trust in the DNS hierarchy.
130
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNSSEC Support
The range of values for the lifetime and rollover time is 1 to 2,147,483,647 seconds
(about 68 years). The default lifetime and rollover time differ for ZSKs and KSKs:
l ZSKs – The default lifetime is 7,776,000 seconds (90 days), and the default rollover
time is 7,171,200 seconds (83 days).
l KSKs – The default lifetime is 31,536,000 seconds (365 days), and the rollover time
is 30,931,200 seconds (358 days).
131
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNSSEC Support
When DNSSEC is enabled, HSM generates a KSK for the GSLB zone, generates a ZSK
for the zone, and signs it with the KSK. The following text is an example of message
that appears in the log.
132
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNSSEC Support
Log Buffer: 30000 Jul 31 2013 06:49:13 Notice [DNS]:succeed to reload the
signature of zone "[Link]"
Jul 31 2013 06:48:58 Notice [CLI]: DNSSEC module:succeed to generate ZSK
test.com_zsk_2013-07-31-06-48-58 for zone [Link]
Jul 31 2013 06:48:58 Notice [CLI]: DNSSEC module:please transfer the DS
RR of zone [Link] to the parent zone for the initial process.
Jul 31 2013 06:48:58 Notice [CLI]: DNSSEC module:succeed to generate KSK
test.com_ksk_2013-07-31-06-48-57 for zone [Link]
The first message, starting at the bottom, indicates a successful generation of a KSK
for child zone [Link]. The next message, which is second from the bottom, is a
reminder to copy the DS resource record for the key to the authoritative DNS server
for the parent zone.
The third message indicates a successful generation of the ZSK for child zone
[Link]. The final message at the top, indicates completion of the rekey process.
CAUTION: Although key generation and rollover are automatic, ACOS does not
automatically send the DS record for the new KSK to the parent zone.
This part of the process must be performed manually. If the default key
generation and rollover settings are used, this process needs to be
performed once a year.
To export a file:
133
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNSSEC Support
After enabling DNSSEC, wait about a minute for the key to be generated. You can use
the export dnssec-ds command to copy the DS resource record for the zone to the
DNS server that is authoritative for the parent zone.
For syntax information, see the Command Line Interface Reference.
The start option initiates a rollover for the specified key type.
For KSK rollover, the ds-ready-in-parent-zone option indicates that the DS record
for the new KSK has been exported to the parent zone. Use this option only after you
have installed the DS record for the new KSK on the authoritative DNS server for the
parent zone. For example:
NOTE: For more information about the supported values, see Key Generation
and Rollover Parameters.
134
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNSSEC Support
DNSSEC
The following topics are covered:
DNSSEC Configuration Example 135
The following are the configuration modes from a device that is configured for
DNSSEC.
135
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNSSEC Support
NOTE: ACOS checks the validity of DNSSEC signatures everyday. This ensures
that if the signatures are due to expire in the next 1 or 2 days, they are
duly resigned well on time.
Configuring GSLB
The following commands configure GSLB.
136
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNSSEC Support
137
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNSSEC Support
ACOS(config-service-ip:vip-5-port:tcp)# health-check-disable
ACOS(config-service-ip:vip-5-port:tcp)# exit
ACOS(config-service-ip:vip-5)# port 21 tcp
ACOS(config-service-ip:vip-5-port:tcp)# health-check-protocol-disable
ACOS(config-service-ip:vip-5-port:tcp)# health-check-disable
ACOS(config-service-ip:vip-5-port:tcp)# exit
ACOS(config-service-ip:vip-5)# exit
ACOS(config)# gslb service-ip vip-6 [Link]
ACOS(config-service-ip:vip-6)# health-check-protocol-disable
ACOS(config-service-ip:vip-6)# health-check-disable
ACOS(config-service-ip:vip-6)# port 80 tcp
ACOS(config-service-ip:vip-6-port:tcp)# health-check-protocol-disable
ACOS(config-service-ip:vip-6-port:tcp)# health-check-disable
ACOS(config-service-ip:vip-6-port:tcp)# exit
ACOS(config-service-ip:vip-6)# port 21 tcp
ACOS(config-service-ip:vip-6-port:tcp)# health-check-protocol-disable
ACOS(config-service-ip:vip-6-port:tcp)# health-check-disable
ACOS(config-service-ip:vip-6-port:tcp)# exit
ACOS(config-service-ip:vip-6)# exit
ACOS(config)# gslb service-ip vip6-1 2001:111::1
ACOS(config-service-ip:vip6-1)# port 80 tcp
ACOS(config-service-ip:vip6-1-port:tcp)# exit
ACOS(config-service-ip:vip6-1)# port 21 tcp
ACOS(config-service-ip:vip6-1-port:tcp)# exit
ACOS(config-service-ip:vip6-1)# exit
ACOS(config)# gslb service-ip vip6-2 2001:111::2
ACOS(config-service-ip:vip6-2)# port 80 tcp
ACOS(config-service-ip:vip6-2-port:tcp)# exit
ACOS(config-service-ip:vip6-2)# port 21 tcp
ACOS(config-service-ip:vip6-2-port:tcp)# exit
ACOS(config-service-ip:vip6-2)# exit
ACOS(config)# gslb service-ip vip6-3 2001:111::3
ACOS(config-service-ip:vip6-3)# port 80 tcp
ACOS(config-service-ip:vip6-3-port:tcp)# exit
ACOS(config-service-ip:vip6-3)# port 21 tcp
ACOS(config-service-ip:vip6-3-port:tcp)# exit
ACOS(config-service-ip:vip6-3)# exit
ACOS(config)# gslb service-ip vip6-4 2001:111::4
ACOS(config-service-ip:vip6-4)# port 80 tcp
ACOS(config-service-ip:vip6-4-port:tcp)# exit
138
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNSSEC Support
139
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNSSEC Support
The dns server command enables server mode, and also enables this ACOS device to
be the authoritative DNS server for the GSLB zones that use this policy.
140
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
DNSSEC Support
141
Location-Based VIP Access
142
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Location-Based VIP Access
ACOS determines a client’s location by looking up the client’s subnet in the geo-
location database that is used by Global Server Load Balancing (GSLB).
NOTE: This feature requires you to load a geo-location database, but does not
require any other configuration of GSLB. The ACOS system image
includes the Internet Assigned Numbers Authority (IANA) database. By
default, the IANA database is not loaded but you can easily load it. For
more information, see Loading the IANA Geo-Location Database.
NOTE: In the current release, geo-location-based VIP access works only if the
class list is imported as a file. The CLI does not support configuration of
class-list entries for this application.
Example
The following class list maps client geo-locations to limit IDs (LIDs), which specify the
maximum number of concurrent connections allowed for clients in the geo-locations.
L US 1
L [Link] 2
143
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Location-Based VIP Access
L [Link] 3
The following commands import the class list to the ACOS device, configure a policy
template, and bind the template to a virtual port. The connection limits specified in
the policy template apply to clients that send requests to the virtual port.
144
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Location-Based VIP Access
--------------------------------------------------------------------------
------
[Link] v 3 1 1 1
[Link]
--------------------------------------------------------------------------
------
Total: 1
Details
To configure geo-location-based access control for a VIP:
1. Configure a black/white list.
You can configure the list by using a text editor or enter the list into the GUI. If
you configure the list by using a text editor, import the list to the ACOS device.
2. Configure an SLB policy (PBSLB) template.
145
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Location-Based VIP Access
In the template, specify the black/white list name, and the actions to perform for
the group IDs in the list.
3. Verify that the geo-location database is loaded.
For more information about loading the geo-location database, see Loading the
IANA Geo-Location Database.
4. Apply the policy template to the virtual port for which you want to control
access.
Methods
You can configure black/white lists in one of the following ways:
l Remote – Use a text editor and import the list to the ACOS device.
l Local – Enter the black/white list in a management GUI window.
With both methods, the syntax is the same. The black/white list must be a text file
that contains entries (rows) in the following format:
The various parameters in the syntax are described in the Black/White List Syntax
Description.
146
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Location-Based VIP Access
L "US" 1
L "[Link]" 2
L "JP" 3
147
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Location-Based VIP Access
NOTE: For more details and information about any of the required fields
on this page, see the latest version of the GUI Online Help.
3. Click Create.
NOTE: For more details and information about any of the required fields
on this page, see the latest version of the GUI Online Help.
5. Click OK.
NOTE: For more information, see the Global Server Load Balancing Guide.
148
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Location-Based VIP Access
CLI Example
The following command imports black/white list “geolist” onto the ACOS device.
The following commands configure a policy template named “geoloc” and add the
black/white list to it. The template is configured to drop traffic from clients in the
geo-location mapped to group 1 in the list.
The following commands apply the policy template to port 80 on virtual server
“vip1”:
149
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Location-Based VIP Access
To view SLB geo-location statistics, use the show slb geo-location command.
Details
By default, when a client requests a connection, the ACOS device checks the
connection count only for the specific geo-location level of the client. If the
connection limit for that specific geo-location level is not reached, the client’s
connection is permitted. Similarly, the permit counter is increased only for that
specific geo-location level.
Geo-location connection limit example shows an example set of geo-location
connection limits and current connections.
Using the default behavior, the connection request from the client at [Link]
is allowed even though CA has reached its connection limit. Similarly, a connection
request from a client at [Link] is allowed. However, a connection request from a
client whose location match is simply “US” is denied.
After these three clients are permitted or denied, the connection permit and deny
counters are increased in the following way:
150
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Location-Based VIP Access
When full-domain checking is enabled, the ACOS device checks the current
connection count not only for the client’s specific geo-location, but for all geo-
locations higher up in the domain tree.
Based on full-domain checking, all three connection requests from the clients in the
example above are denied. This is because the US domain has reached its connection
limit. Similarly, the counters for each domain are updated as follows:
l US – Deny counter is incremented by 1.
l [Link] – Deny counter is incremented by 1.
151
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Location-Based VIP Access
NOTE: You must enable or disable this option before you enable GSLB.
Changing the state of this option while GSLB is running can cause the
related statistics counters to be incorrect.
Details
You can enable sharing of statistics counters for all virtual servers and virtual ports
that use a PBSLB template. This option causes the following counters to be shared by
the virtual servers and virtual ports that use the template:
l Permit
l Deny
l Connection number
l Connection limit
152
ACOS 7.0.2 Application Delivery Controller Security Guide Feedback
Location-Based VIP Access
5. Select Share.
6. Click OK.
NOTE: You must enable or disable this option before you enable GSLB.
Changing the state of this option while GSLB is running can cause the
related statistics counters to be incorrect.
153
©2025 A10 Networks, Inc. All rights reserved. A10 Networks, the A10 Networks logo, ACOS, A10 Thunder,
Thunder TPS, A10 Harmony, SSLi and SSL Insight are trademarks or registered trademarks of A10 Networks, Inc. in
the United States and other countries. All other trademarks are property of their respective owners. A10
Networks assumes no responsibility for any inaccuracies in this document. A10 Networks reserves the right to
change, modify, transfer, or otherwise revise this publication without notice. For the full list of trademarks, visit:
Contact Us
[Link]/company/legal/trademarks/.