aFleX Scripting Language Guide
aFleX Scripting Language Guide
2
aFleX Scripting Language Reference
October, 2025
© 2025 A10 Networks, Inc. All rights reserved.
Information in this document is subject to change without notice.
PATENT PROTECTION
A10 Networks, Inc. products are protected by patents in the U.S. and elsewhere. The following website is provided
to satisfy the virtual patent marking provisions of various jurisdictions including the virtual patent marking
provisions of the America Invents Act. A10 Networks, Inc. products, including all Thunder Series products, are
protected by one or more of U.S. patents and patents pending listed at:
a10-virtual-patent-marking.
TRADEMARKS
A10 Networks, Inc. trademarks are listed at: a10-trademarks
CONFIDENTIALITY
This document contains confidential materials proprietary to A10 Networks, Inc. This document and information
and ideas herein may not be disclosed, copied, reproduced or distributed to anyone outside A10 Networks, Inc.
without prior written consent of A10 Networks, Inc.
DISCLAIMER
This document does not create any express or implied warranty about A10 Networks, Inc. or about its products or
services, including but not limited to fitness for a particular use and non-infringement. A10 Networks, Inc. has made
reasonable efforts to verify that the information contained herein is accurate, but A10 Networks, Inc. assumes no
responsibility for its use. All information is provided "as-is." The product specifications and features described in
this publication are based on the latest information available; however, specifications are subject to change without
notice, and certain features may not be available upon initial product release. Contact A10 Networks, Inc. for
current information regarding its products or services. A10 Networks, Inc. products and services are subject to A10
Networks, Inc. standard terms and conditions.
ENVIRONMENTAL CONSIDERATIONS
Some electronic components may possibly contain dangerous substances. For information on specific component
types, please contact the manufacturer of that component. Always consult local authorities for regulations
regarding proper disposal of electronic components in your area.
FURTHER INFORMATION
For additional information about A10 products, terms and conditions of delivery, and pricing, contact your nearest
A10 Networks, Inc. location, which can be found by visiting [Link].
Table of Contents
Getting Started 20
Advantages of Using aFleX Policies 22
aFleX Processing Order 22
Packet Processing Order for Layer 4 Virtual Ports 23
Packet Processing Order for Layer 7 Virtual Ports 23
Packet Processing Example 23
When aFleX Policy Changes Take Effect 24
Support for Multiple aFleX Policies on a Single Virtual Port 24
Configure aFleX for GTP Director 24
Ruleset for Defining Payload 25
Syntax to Define Ruleset 25
Configuring aFleX for GTP Director 26
aFleX CLI Commands 36
aFleX Online Help 37
aFleX Script Rename 38
Copy aFleX Script 39
Maximum File Size of aFleX Scripts 39
Maximum Number of aFleX Scripts 40
aFleX Syntax 40
Local Variable Syntax 40
Global Variable Syntax 41
aFleX Script Components 42
aFleX Context 42
Tcl Symbols 43
Example aFleX Scripts 44
3
ACOS 7.0.2 aFleX Scripting Language Reference Guide
Contents
aFleX Operators 60
Logical Operators 61
and 61
not 61
or 62
Relational Operators 62
contains 63
ends_with 63
equals 64
matches 64
matches_regex 65
starts_with 66
aFleX Events 67
Overview 68
Global Events 69
RULE_INIT 70
LB_FAILED 71
LB_SELECTED 74
AAM Events 78
4
ACOS 7.0.2 aFleX Scripting Language Reference Guide
Contents
AAM_AUTHENTICATION_INIT 79
AAM_AUTHORIZATION_INIT 81
AAM_AUTHORIZATION_CHECK 83
AAM_RELAY_INIT 85
Authentication Event 87
AUTH_RESULT 87
Database Load-Balancing Events 88
DB_COMMAND 89
DB_QUERY 90
Diameter Load-Balancing Events 93
DIAMETER_ANSWER 94
DIAMETER_ANSWER_SEND 95
DIAMETER_REQUEST 97
DIAMETER_REQUEST_SEND 98
DNS Events 101
DNS_REQUEST 102
DNS_RESPONSE 105
Financial Information eXchange Events 108
FIX_REQUEST 109
FIX_RESPONSE 110
HTTP Events 113
HTTP_REQUEST 113
HTTP_REQUEST_DATA 120
HTTP_REQUEST_SEND 125
HTTP_RESPONSE 129
HTTP_RESPONSE_CONTINUE 134
HTTP_RESPONSE_DATA 138
ICAP Events 143
ICAP_REQUEST 144
ICAP_RESPONSE 144
IP, TCP, and UDP Events 146
5
ACOS 7.0.2 aFleX Scripting Language Reference Guide
Contents
CLIENT_ACCEPTED 147
CLIENT_CLOSED 151
CLIENT_DATA 155
SERVER_CLOSED 160
SERVER_CONNECTED 163
SERVER_DATA 167
MQTT Events 171
MQTT_CLIENT_MESSAGE 171
MQTT_SERVER_MESSAGE_DATA 172
MQTT_SERVER_MESSAGE 173
MQTT_CLIENT_MESSAGE_DATA 175
MQTT_PUBLISH 176
MQTT_SUBSCRIBE 177
RAM Caching Events 179
CACHE_REQUEST 180
CACHE_RESPONSE 182
SIP Events 185
SIP_REQUEST 186
SIP_REQUEST_SEND 188
SIP_RESPONSE 191
SMTP Events 194
SMTP_MAIL 195
SMTP_EHLO 195
SSL Events 196
CLIENTSSL_CLIENTCERT 197
CLIENTSSL_CLIENTHELLO 200
CLIENTSSL_DATA 202
CLIENTSSL_HANDSHAKE 205
SERVERSSL_CLIENTHELLO_SEND 208
SERVERSSL_DATA 211
SERVERSSL_HANDSHAKE 214
6
ACOS 7.0.2 aFleX Scripting Language Reference Guide
Contents
SERVERSSL_SERVERCERT 216
SERVERSSL_SERVERHELLO 217
7
ACOS 7.0.2 aFleX Scripting Language Reference Guide
Contents
ip_ttl 240
local_addr 241
log 241
lwnode 243
md5 244
members 245
nexthop 245
node 246
ntohl 247
ntohs 247
persist 248
pool 252
redirect 253
reject 253
remote_addr 254
rsha256 254
return 257
server_addr 257
server_port 258
serverside 258
session 259
encoding 260
sha1 260
sha256 261
snat 261
snatpool 262
string map 263
substr 264
switch 265
table 268
use 269
8
ACOS 7.0.2 aFleX Scripting Language Reference Guide
Contents
utc_to_numeric_date 270
virtual 270
when 271
whereis 271
Global Variable Commands 277
array 278
get 278
incre 279
set 279
unset 279
AAM Commands 281
AAM::attribute 282
AAM::attribute_collection 283
AAM::authentication 284
AAM::authorization 286
AAM::bypass 287
AAM::client 288
AAM::relay 289
AAM::saml 290
AAM::session 292
Example AAM aFleX Scripts 293
Example 1: Processing aFlex Commands in AAM_AUTHORIZATION_CHECK Event 294
Example 2: Classifying AAA Policy Result while Authenticating and Authorizing 295
Example 3: Setting Authentication Service-group by Requested Domain 295
Example 4: Setting Authorization Server by Client IP Address 296
Example 5: Selecting Domain-based Auth Server 296
Example 6: Get Scripts for Domain-based Auth Server Selection 298
Example 7: Getting a constructed JWT from a Session 299
AES Commands 301
AES::decrypt 302
AES::encrypt 303
9
ACOS 7.0.2 aFleX Scripting Language Reference Guide
Contents
AES::key 304
Application Firewall Commands 305
APPCLS::application 306
Category Commands 308
CATEGORY::lookup 309
Class List Commands 312
CLASS::exists 313
CLASS::match 314
For Class List of Types Other than String 314
For Class Lists of Type String 315
CLASS::names 317
CLASS::type 318
Compression Commands 321
COMPRESS::brotli 321
COMPRESS::disable 323
COMPRESS::enable 323
COMPRESS::gzip 324
COMPRESS::method_order 326
Database Load-Balancing Commands 328
DB::command 329
DB::query 329
Diameter Load-Balancing Commands 330
DIAMETER::app_id 331
DIAMETER::avp 331
DIAMETER::cmd_code 335
DIAMETER::length 336
DIAMETER::version 337
DNS Commands 338
DNS::additional 339
DNS::answer 339
DNS::authority 340
10
ACOS 7.0.2 aFleX Scripting Language Reference Guide
Contents
DNS::cache 341
DNS::class 342
DNS::header 343
DNS::is_dnssec 344
DNS::len 345
DNS::name 345
DNS::opt 346
DNS::query 347
DNS::question 348
DNS::rdata 349
DNS::return 349
DNS::rr 350
DNS::ttl 351
DNS::type 351
Financial Information eXchange Commands 353
FIX::begin_string 354
FIX::body_length 354
FIX::msg_seq_num 355
FIX::msg_type 355
FIX::sender_compid 356
FIX::sending_time 356
FIX::target_compid 357
HTTP Commands 359
HTTP::close 361
HTTP::collect 361
HTTP::cookie 364
HTTP::disable 368
HTTP::fallback 369
HTTP::header 370
HTTP::host 372
HTTP::is_keepalive 373
11
ACOS 7.0.2 aFleX Scripting Language Reference Guide
Contents
HTTP::is_redirect 374
HTTP::method 375
HTTP::password 375
HTTP::path 376
HTTP::payload 377
HTTP::query 378
HTTP::redirect 379
HTTP::release 379
HTTP::request 380
HTTP::request_num 381
HTTP::respond 381
HTTP::retry 383
HTTP::scheme 384
HTTP::status 384
HTTP::stream 385
HTTP::uri 386
HTTP::username 387
HTTP::version 387
ICAP Commands 389
ICAP::disable 390
ICAP::header add 390
ICAP::header remove 391
ICAP::header replace 391
ICAP::header replace-all 392
ICAP::header values 392
ICAP::method 393
ICAP::reqmod_valid 393
ICAP::respmod_valid 394
ICAP::status 394
ICAP::uri 395
IP Commands 396
12
ACOS 7.0.2 aFleX Scripting Language Reference Guide
Contents
IP::addr 397
IP::category 398
IP::client_addr 399
IP::local_addr 400
IP::payload 401
IP::protocol 402
IP::remote_addr 402
IP::reputation 403
IP::server_addr 404
IP::stats 405
IP::tos 406
IP::ttl 407
IP::version 408
Limit ID Commands 409
LID::conn_limit 410
LID::conn_rate_limit 411
LID::exists 412
LID::nat_pool 413
LID::request_limit 414
LID::request_rate_limit 415
LID::type 416
Link Commands 418
LINK::lasthop 419
LINK::nexthop 419
LINK::vlan_id 420
Load-balancing Commands 421
LB::down 422
LB::reselect 422
LB::server 424
LB::status 426
MQTT Commands 429
13
ACOS 7.0.2 aFleX Scripting Language Reference Guide
Contents
MQTT::clean_session_flag 431
MQTT::client_id 431
MQTT::collect 431
MQTT::drop 432
MQTT::dup_flag 433
MQTT::keep_alive 433
MQTT::length 434
MQTT::packet_id 434
MQTT::password 435
MQTT::payload 435
MQTT::payload_length 436
MQTT::protocol_name 437
MQTT::protocol_version 437
MQTT::qos 438
MQTT::replace 439
MQTT::respond 440
MQTT::retain_flag 441
MQTT::return_code 441
MQTT::return_code_list 442
MQTT::session_present_flag 442
MQTT::topic 443
MQTT::type 444
MQTT::username 445
MQTT::will 446
Policy-Based SLB Commands 448
POLICY::bwlist id 449
POLICY::source_rule 450
RADIUS Message Load-balancing Commands 451
RADIUS::avp 452
RADIUS::code 453
RADIUS::id 454
14
ACOS 7.0.2 aFleX Scripting Language Reference Guide
Contents
RADIUS::length 454
RAM Caching Commands 455
CACHE::age 456
CACHE::disable 456
CACHE::enable 457
CACHE::expire 458
CACHE::headers 459
CACHE::hits 459
Resolve Commands 461
RESOLVE::lookup 462
SIP Commands 464
SIP::call_id 465
SIP::from 465
SIP::header 466
SIP::method 467
SIP::respond 467
SIP::response 468
SIP::to 469
SIP::uri 469
SIP::via 470
SIP Command Examples 471
Example 1 472
Example 2 474
Example 3 475
SMTP Commands 478
SMTP::mail 479
SMTP::greet 479
SMTP::ehlo 480
SSL Commands 481
SSL::authenticate 482
SSL::cert 483
15
ACOS 7.0.2 aFleX Scripting Language Reference Guide
Contents
SSL::cipher 484
SSL::collect 485
SSL::disable 486
SSL::enable 487
SSL::extensions 487
SSL::hostname 488
SSL::mode 490
SSL::payload 490
SSL::release 492
SSL::renegotiate 493
SSL::respond 494
SSL::session invalidate 496
SSL::session 497
SSL::sessionid 498
SSL::sessionsecret 498
SSL::template 499
SSL::verify_result 500
SSLI::bypass 501
SSLI::cache_cert 501
SSLI::drop 502
SSLI::inspect 502
Statistics Commands 504
STATS::clear 505
STATS::get 506
Table Commands 508
table add 510
table append 510
table delete 511
table incr 511
table keys 512
table lifetime 512
16
ACOS 7.0.2 aFleX Scripting Language Reference Guide
Contents
17
ACOS 7.0.2 aFleX Scripting Language Reference Guide
Contents
TEMPLATE::client_ssl 545
TEMPLATE::conn_reuse 546
TEMPLATE::exists 547
TEMPLATE::http 548
TEMPLATE::server_ssl 550
TEMPLATE::tcp 551
TEMPLATE::udp 551
Time Commands 553
TIME::clock 554
UDP Commands 558
UDP::client_port 559
UDP::local_port 559
UDP::payload 560
UDP::remote_port 561
UDP::respond 562
UDP::server_port 563
URI Commands 565
URI::basename 566
URI::decode 566
URI::encode 567
URI::params 567
URI::path 568
URI::query 568
URL Commands 570
URL::reputation 571
X509 Commands 573
X509::extensions 574
X509::hash 574
X509::issuer 575
X509::not_valid_after 576
X509::not_valid_before 576
18
ACOS 7.0.2 aFleX Scripting Language Reference Guide
Contents
X509::serial_number 577
X509::signature_algorithm 578
X509::subject 578
X509::subject_public_key 579
X509::subject_public_key_RSA_bits 579
X509::subject_public_key_type 580
X509::text 580
X509::verify_cert_error_string 581
X509::version 582
X509::whole 582
19
Getting Started
The aFleX scripting language is a powerful inline custom scripting engine that
provides in-depth, granular control of inspection and redirection policies (filter,
drop, redirect). The aFleX scripting language is based on the Tool Command
Language (Tcl) programming standard for simplicity and familiarity. For an aFleX
policy to work, it must be bound to a virtual port on the ACOS device. Then the
aFleX policy can make policy decisions by inspecting the payload packets from all
the traffic going through the virtual port.
Below is an example of a simple aFlex script:
when CLIENT_ACCEPTED {
if { [IP::addr [IP::client_addr] equals [Link]] } {
pool www_service_group
}
}
The chapters provide detailed information about working with aFleX policies.
20
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
21
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
22
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
23
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
NOTE: Server template limits are applied for both service-group and server
selection. Commands that call for server selection (i.e., “node”, “pool”,
“persist”, etc.) will enforce server template limits on the selected
server. As a result, new connections that match a persist uie entry may
be unable to use the rport and a default server selection will occur
instead. To prevent default server selection, use the def-selection-
if-pref-failed-disable command for the vport.
24
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
payload. The aFleX ruleset can be updated as per the requirement of the
organization. The sections mentioned below include information about configuring
aFleX for GTP Director.
Rule1: If IMSI starts with ‘466924’ and APN starts with ‘internet’ then
direct to SG1.
Rule 2: If IMSI starts with ‘466777’ and APN starts with ‘internet’ then
direct to SG2.
Rule 3: If IMSI starts with ‘355000’ and APN starts with ‘pan’ then direct
to SG3.
25
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
l Conditions— ':'
l Parameter— '-'
l Service-group— ' ' (space)
The ruleset for match type is added in the following aFleX example:
set::RuleSets {
1:imsi-e-3930:apn-s-int:pdna-q-[Link]:sg2
71:mei-e-4916:apn-s-int:pdn-q-3:sg2
72:mei-e-4916:apn-s-int:ambruplink-q-150000:ambrdownlink-q-800000:sg2
75:mei-e-4916:apn-s-int:pdn-q-3:sg2
76:imsi-e-3930:apn-s-int:msisdn-e-066821:sg2
79:mei-e-4916:apn-s-int:pdna-q-[Link]:sg2
82:imsi-e-3930:apn-s-int:rat-q-6:sg2
83:imsi-e-3930:apn-s-int:mcc-e-440:mnc-e-10:sg2
86:imsi-e-3930:apn-s-int:tac-e-85:tcellid-e-641:sg2
87:imsi-e-3930:apn-s-int:fteidkey-e-4eeb:fteid-q-[Link]:sg2
95:imsi-e-3930:apn-s-int:cc-e-a00:sg2
99:mei-e-4916:apn-s-int:pdn-q-3:sg2
}
ii. Copy and paste the aFlex and insert ‘. ‘ (Dot) at the end
Example:
26
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
NOTE: Type in your aFleX script (type ‘.’ on a line by itself when
done)
when HTTP_REQUEST {
HTTP::redirect [Link]
}
.
aFleX test1 created; syntax check passed
ACOS(config)#
27
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
28
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
29
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
30
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
31
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
NOTE:
l Only GTPv1-C and GTPv2-C is supported.
l The rule set defined is not in preferential order. However, the match
is done in the order in which the ruleset is configured and the first
match is chosen
l Up to 64 sets of match criteria are supported.
l Up to 16 service-groups are supported and if none of the configured
set of Match criteria is matched, then the default service-group
configured under the VIP is used to select one of the PGW’s.
The following fields are extracted and can be used to match the GTPv1 requests.
32
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
33
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
34
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
35
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
Example:
The packet can contain IMSI, MEI, MCC, MNC. Another packet might contain IMSI,
MEI, RAT.
36
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
NOTE: aFleX help information is available through the CLI only and not
accessible from the GUI.
Command Description
aflex help events View help for aFleX events.
aflex help global View help for aFleX global commands.
aflex help operators View help for aFleX operators.
aflex help command View help for a specific aFleX command.
TIME::clock seconds
- Returns the current time in the unit of seconds. The function is used
in SMP environment for high-performance processing.
TIME::clock milliseconds
37
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
38
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
The list of aFleX scripts reappears showing the new name. The GUI also automatically
updates the aFleX name everywhere the script is used. For example, if the script is
already bound to a virtual port, the script’s name is automatically updated in the
virtual port’s configuration. You do not need to manually update the virtual port
configuration.
NOTE: Scripts that contain syntax errors cannot be copied. The CLI console
notifies you if copy failure is due to a syntax error.
39
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
aFleX Syntax
An aFleX script is a Tcl-like script. Every command call has the following form:
command arg1 arg2 arg3 ...
The aFleX interpreter takes each word of command call and evaluates it. After
evaluation of each word, the first word (command) is considered to be a function
name. The function is executed with the rest of the words as arguments.
If a word is surrounded by curly braces { }, this word is unaffected and the
substitution is thus not applicable. Inside the braces, there may be spaces and
carriage returns. The { } may also be nested.
40
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
The first line beginning with set c sets the value of the specified local variable. The
local variable is only used within the current aFleX script. Replace “example text”
with the value you want to set for c; each variable must be set first before it can be
called.
The aFleX interpreter sees the remainder of this script as 5 words:
1. ' if' is the first word. There is nothing to be evaluated.
2. ' $c == "Exit"' is the second word. Because of the surrounding curly braces,
there is no further evaluation on this word.
3. ' log "Goodbye!"' is the third word. For the same reason as the second word, no
further evaluation is needed.
4. ' else' is the fourth word. There is nothing to be evaluated.
5. ' log "Hello!"' is the fifth word. No further evaluation is needed.
The first word, ' if', is taken as the command and this command is executed with the
4 following words as parameters. Later, the condition ' $c == "Exit"' is evaluated,
during the execution of the if command.
Use unset c to unset the local variable.
41
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
In the line beginning with set client_ip [Link], client_ip is a local variable, as
previously discussed, which can be used within the current script. The next line
beginning with table set active_clients $client_ip 1 sets a global table variable named active_
clients with a key of $client_ip and a value of “1.” Replace the name, key, and
value with the terminology of your choice. Global table variables can be used by all
aFleX scripts.
aFleX Context
aFleX scripts support context for specifying either client or server side:
l Each event has a default context of either client-side or server-side.
l Key words: “clientside” or “serverside”
l Only specify the context keywords if you want to change default context.
Example This aFleX script uses the default CLIENT side association to the
REMOTE_ADDR. Because CLIENT_ACCEPTED has a default context of
clientside, the remote_addr field is automatically assigned to clientside.
when CLIENT_ACCEPTED {
if { [IP::addr [IP::remote_addr] equals [Link]] } {
pool www_service_group
}
}
To change the default context of any aFleX script, use the clientside
or serverside key words.
42
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
Example This aFleX policy switches the remote_addr field to the clientside from
the default serverside association with the SERVER_CONNECTED event.
when CLIENT_ACCEPTED {
if { [IP::addr [ clientside {IP::remote_addr}] equals
[Link] ] } {
pool www_service_group
}
}
Tcl Symbols
The Tcl symbols listed in Table 5 have special meanings.
43
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
NOTE: Not all Tcl commands and symbols are supported. See Disabled Tcl
Commands.
Example Node Selection—This aFleX script uses the node command to select one
specific server to send the traffic to.
when HTTP_REQUEST {
if { [HTTP::uri] ends_with ".gif" } {
node [Link] 80
}
}
Example IP Packet Header Query (IP Address)—This example shows that the
traffic from client in [Link]/16 subnet is directed to a special
service group called “192_168_service_group”.
when CLIENT_ACCEPTED {
if { [IP::addr [IP::client_addr] equals [Link]/16] }
{
pool 192_168_service_group
} else {
pool www_service_group
}
}
44
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Getting Started
Example IP Packet Header Query (ToS Level)—This example shows the ToS field
being inspected for clientside ToS value of “16”.
when CLIENT_ACCEPTED {
if { [IP::tos] == 16 } {
pool priority_service_group
} else {
pool www_service_group
}
}
Example TCP Query—This aFleX script uses the payload field to check for the
words TOP or BOT to properly redirect traffic.
when CLIENT_DATA {
if { [TCP::payload] contains "TOP" } {
pool top_service_group
} elseif { [substr[TCP::payload] 50, 3] equals "BOT" } {
pool bot_service_group
} else {
pool www_service_group
}
}
45
Applying aFleX Scripts To Virtual Ports
NOTE: You do not need to unbind an aFleX script before renaming it. The
ACOS device automatically updates the configuration wherever the
renamed script is used. For more information, see aFleX Script
Rename.
46
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Applying aFleX Scripts To Virtual Ports
Now, the vport is not automatically marked UP when the aFleX policy is bound,
and the vport status will depend on the service group status as usual.
NOTE: For virtual port type fast-HTTP, aFleX commands that change the HTTP
header or payload are not supported.
47
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Applying aFleX Scripts To Virtual Ports
NOTE: These scripts are intended for educational purposes to assist new
users. A10 Networks does not guarantee the sample scripts will work in
all contexts and is not liable for damages that result from the
misapplication of preloaded aFleX scripts.
48
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Applying aFleX Scripts To Virtual Ports
You can specify one script with the command. Repeat the command for each
additional script to add.
The scripts will be processed in the order you add them, starting with the first script
you add. To re-order the scripts, do either of the following:
l Use the GUI. (See Configure using GUI.)
l In the CLI, use the no aflex name command to remove the scripts from the virtual
port, then re-add them in the correct order.
CLI Example
The example mentioned below explains how to import an aFleX policy onto the ACOS
device and bind it to a virtual port.
when RULE_INIT {
array set sg_array [list "[Link]" "sg1" "[Link]" "sg2"
"[Link]" "sg2"]
}
when HTTP_REQUEST {
set host [HTTP::host]
if { [info exists $sg_array($host)] } {
log "host $host -> pool $sg_array($host)"
pool $sg_array($host)
}
}
49
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Applying aFleX Scripts To Virtual Ports
1. Log on to the ACOS device through the CLI, and access Global configuration
mode.
ACOS>enable
Password:
ACOS#config
ACOS(config)#
50
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Applying aFleX Scripts To Virtual Ports
4. Use the import command to import the aFleX policy (“[Link]”) onto the ACOS
device and rename it “my_aflex”:
ACOS(config)#import aflex my_aflex scp://[Link]/aflex/[Link]
User name []?***
Password []?***
Importing ... Done.
ACOS(config)#
While importing the aFleX policy, the ACOS device checks for syntax errors. If any
syntax errors are found, error messages are displayed. You can modify an aFleX
policy and import it again until it passes the syntax check.
5. Use the show aflex command to view all aFleX policies on the ACOS device:
ACOS(config)#show aflex
Total aFlex number: 7
Max aFlex file size: 32K
Name Syntax Virtual port
----------------------------------------------
host_switching Check No
http_payload_replace Check No
http_respond Check No
logging_clients Check No
my_aflex Check No
redirect1 Check No
redirect2 Check No
redirect_rewrite Check No
6. To display the aFleX policy, use the show aflex aflex-name command:
ACOS(config)#show aflex my_aflex
when RULE_INIT {
array set ::SG_ARRAY [list "[Link]" "sg1" "[Link]" "sg2"
"[Link]" "sg2"]
51
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Applying aFleX Scripts To Virtual Ports
when HTTP_REQUEST {
set host [HTTP::host]
if { [info exists ::SG_ARRAY($host)] } {
log "host $host -> pool $::SG_ARRAY($host)"
pool $::SG_ARRAY($host)
}
}
7. Configure a virtual server and bind the aFleX policy to a virtual port on the virtual
server:
ACOS(config)#slb virtual-server v30 [Link]
ACOS(config-slb vserver)#port 80 http
ACOS(config-slb vserver-vport)#aflex my_aflex
ACOS(config-slb vserver-vport)#exit
ACOS(config-slb vserver)#exit
ACOS(config)#
8. Show the aFleX policy list again to verify that the aFleX policy is now bound to a
virtual port:
ACOS(config)#show aflex
Total aFlex number: 7
Max aFlex file size: 32K
Name Syntax Virtual port
----------------------------------------------
host_switching Check No
http_payload_replace Check No
http_respond Check No
logging_clients Check No
my_aflex Check Bind
redirect1 Check No
redirect2 Check No
redirect_rewrite Check No
52
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Applying aFleX Scripts To Virtual Ports
The CLI enters the input mode for the script text.
53
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Applying aFleX Scripts To Virtual Ports
2. Type or copy-and-paste the script. If you type the script, use the Enter key at the
end of each line.
3. To complete the input process, type “ . ” (period) on a separate line and press
Enter.
NOTE:
l You do not need to save the configuration (write memory) to save
the aFleX script. The script is automatically added to a persistent
data folder and remains available across reboots.
l Regardless of how an aFleX script is added to the ACOS device, the
script does not take effect until you apply it to a virtual port.
Syntax Check
After you finish entering the script text, the CLI performs a syntax check and displays
one of the following messages:
l aFleX aflex-name created; syntax check passed. – Indicates the syntax is
valid.
l aFleX aflex-name created; syntax check failed. – Indicates the syntax is not
valid. In this case, see Troubleshooting aFleX Syntax Errors.
l This aFleX already exists. – Indicates that another aFleX script with the same
name is already on the ACOS device.
The same name can be used in different partitions, but must be unique within a
given partition.
54
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Applying aFleX Scripts To Virtual Ports
55
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Applying aFleX Scripts To Virtual Ports
GUI.
l If Local is selected, you will input the contents of an aFleX script directly into a
field in the GUI. For configuration information, see Import an aFleX Script Using
the GUI
4. Bind the aFleX script to a virtual port. For further information about this step,
see Bind the aFleX Policy to a Virtual Port.
NOTE: You edit an aFleX policy by clicking Edit in the Actions column next to
that aFleX policy’s name. You can delete an existing aFleX policy by
selecting the checkbox located on the left of its name, then clicking
Delete .
56
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Applying aFleX Scripts To Virtual Ports
NOTE: You edit an aFleX policy by clicking Edit in the Actions column next to
that aFleX policy’s name. You can delete an existing aFleX policy by
selecting the checkbox located on the left of its name, then clicking
Delete .
57
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Applying aFleX Scripts To Virtual Ports
In this case, you can fix the script using either CLI or GUI.
58
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Applying aFleX Scripts To Virtual Ports
59
aFleX Operators
60
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Operators
Logical Operators
Logical operators are used to compare numeric values to one another. They are
compatible with all the events, and compatible with any command that has a
numeric value (as opposed to a string value).
The following logical operators are supported:
l and
l not
l or
and
Description Performs a logical “and” comparison between two values.
Example Use the following example to compare the values for HTTP::host and
HTTP::uri:
when HTTP_REQUEST {
if { ([HTTP::host] equals "[Link]") and
([HTTP::uri] starts_with "/blog") } {
pool www_service_group
} else {
pool static_service_group
}
}
not
Description Performs a logical “not” on a value.
61
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Operators
Example Use the following example to see if HTTP::uri does not start with a
specified string:
when HTTP_REQUEST {
if { not ([HTTP::uri] starts_with "/images") } {
pool www_service_group
} else {
pool static_service_group
}
}
or
Description Performs a logical “or” comparison between two values.
Relational Operators
Relational operators are used to compare strings to one another. They are
compatible with all events, and compatible with any command that has a string value
(as opposed to a numeric value).
The following relational operators are supported:
l contains
l ends_with
62
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Operators
l equals
l matches
l matches_regex
l starts_with
contains
Description Tests whether one string (string1) contains another string (string2).
ends_with
Description Tests whether one string (string1) ends with another string (string2).
Example Use the following example to test if HTTP::uri ends with “.html” or
“.asp”:
when HTTP_REQUEST {
if { [HTTP::uri] ends_with ".html" } {
pool static_service_group
} elseif { [HTTP::uri] ends_with ".asp" } {
pool dynamic_service_group
}
}
63
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Operators
equals
Description Tests whether one string equals another string.
Example Use the following example to test if the domain of HTTP::host equals
“com”:
when HTTP_REQUEST {
if { [domain [HTTP::host] 1] equals "com" } {
pool www_service_group
}
}
matches
Description Tests whether one string matches another string.
NOTE: The matches operator uses the same comparison as the Tcl "string
match" command, which functions like a cut-down regular expression.
For the two strings to match, their contents must be identical except
that the following special sequences may appear in the pattern:
• * – Matches any sequence of characters in string, including a null
string.
• ? – Matches any single character in string.
• [chars] – Matches any character in the set given by chars. If a
sequence of the form x-y appears in chars, then any character
between x and y, inclusive, will match. When used with -nocase,
the end points of the range are converted to lower case first.
Whereas {[A-z]} matches '_' when matching case-sensitively ('_'
falls between the 'Z' and'a'), with -nocase this is considered to be
like {[A-Za-z]}.
64
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Operators
matches_regex
Description Tests whether one string matches a regular expression or another
string.
65
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Operators
starts_with
Description Tests whether one string (string1) starts with another string (string2).
Example Use the following example to test if HTTP::uri starts with “/static”:
when HTTP_REQUEST {
if { [HTTP::uri] starts_with "/static" } {
pool static_service_group
} else {
pool dynamic_service_group
}
}
66
aFleX Events
67
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
Overview
aFleX scripts are event-driven. The ACOS device triggers an aFleX policy based on a
specified event. For example, if an aFleX policy is configured to be triggered by the
HTTP_REQUEST event, the ACOS device triggers the aFleX policy when an HTTP
request is received.
Event declarations are made with the “when” keyword followed by the event name.
Example
when CLIENT_ACCEPTED {
if { [IP::addr [IP::remote_addr] equals [Link] ] } {
pool example_service_group
}
}
For information about other script components, see aFleX Script Components.
68
Global Events
This section describes the global events.
For information about aFleX events, see aFleX Events.
69
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
RULE_INIT
Description Use this event to immediately set global system variables; when an
aFleX script containing a RULE_INIT event is added to the virtual server
port, the RULE_INIT event is immediately triggered and global variables
are set.
The prefix placed before the variable specifies the variable scope. It
specifies whether to initialize that variable for all aFleX policies, or only
for the current aFleX policy.
Prefix Scope
:: Applies in the same aFlex policy. This variable cannot
be set or read by any other aFlex policies. Once a
global variable is defined, it cannot be deleted.
::global:: Applies to all aFleX policies. This variable can be set
or read by all aFleX policies on the ACOS device
regardless of partition or CPU.
70
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• unset
LB_FAILED
Description Execute specific aFleX commands when the ACOS device is not able to
select a node for the incoming request (for example, if all nodes in the
pool are down or all their connection limits have been reached).
When this event is used with aFleX scripts bound to TCP virtual ports,
it is triggered by the following conditions:
• The selected server is unreachable (no route host).
• The selected server is non-responsive (fails to respond to a
connection request)
• The selected server sent a TCP Reset. In order to enable this
trigger, configure inband-health-check resel-on-reset on a port
template attached to the service group or real server port
associated with the virtual port.
71
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• CLASS::match
• CLASS::names
• CLASS::type
72
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• cpu usage
• domain
• drop
• encoding
• event
• findstr
• getfield
• htonl
• htons
• if
• log
• md5
• members
• nexthop
• ntohl
• ntohs
• persist
• pool
• reject
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
• whereis
73
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
Example Use the following example to add a node to the error service group
“backup_service_group” when it fails.
when LB_FAILED {
pool backup_service_group
}
LB_SELECTED
Description Execute specific aFleX commands when a pool member is selected.
74
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• IP::version
75
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• encoding
• event
• findstr
• getfield
• htonl
• htons
• if
• log
• md5
• members
• nexthop
• ntohl
• ntohs
• persist
• reject
• return
• serverside
• encoding
• sha1
• snat
• snatpool
• string map
• substr
• switch
• use
• virtual
• whereis
76
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
Example Use the following example to add a pool member to a source NAT pool
when the member is selected.
when LB_SELECTED {
if { [IP::addr [IP::remote_addr] equals "[Link]"] } {
snatpool snat-internal
}
}
77
AAM Events
The following Authentication Authorization Management (AAM) events are
available:
l AAM_AUTHENTICATION_INIT
l AAM_AUTHORIZATION_CHECK
l AAM_AUTHORIZATION_INIT
l AAM_RELAY_INIT
NOTE: aFleX scripts containing AAM events are only valid on HTTP and HTTPS
virtual ports. Also, AAM events are not triggered for OCSP
configurations.
78
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
AAM_AUTHENTICATION_INIT
Description Execute specific aFleX scripts during preparation before AAM
authentication.
79
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• if
• log
• md5
• members
• nexthop
• ntohl
• ntohs
• persist
• reject
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
80
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
Example Use the following example to append a different prefix to the username
for authentication and relay. The ACOS device will use the username
AUTH_$name for authentication, RELAY_$name for relay, and $name for
authorization.
when AAM_AUTHENTICATION_INIT {
set name [AAM::client get username]
AAM::authentication set username "AUTH_$name"
AAM::relay set username "RELAY_$name"
}
AAM_AUTHORIZATION_INIT
Description Execute specific aFleX scripts in preparation for AAM authentication
and relay.
81
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• findstr
• getfield
• htonl
• htons
• if
• log
• md5
• members
• nexthop
• ntohl
• ntohs
• persist
• reject
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
82
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
Example For additional examples, see Example 7: Getting a constructed JWT from
a Session.
AAM_AUTHORIZATION_CHECK
Description Execute specific aFleX commands for AAM authorization.
83
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• findstr
• getfield
• htonl
• htons
• if
• log
• md5
• members
• nexthop
• ntohl
• ntohs
• persist
• reject
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
84
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
AAM_RELAY_INIT
Description Execute specific aFleX scripts during preparation before AAM relay.
85
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• getfield
• htonl
• htons
• if
• log
• md5
• members
• nexthop
• ntohl
• ntohs
• persist
• reject
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
86
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
Example Use the following example to append a different prefix to the username
for relay. The ACOS device will append AUTH_ to the username, and set
this new username to $relay_name for relay.
when AAM_RELAY_INIT {
set relay_name "AUTH_"
append relay_name [AAM::relay get username]
AAM::relay set username $relay_name
}
Authentication Event
The following Authentication event is available:
l AUTH_RESULT
AUTH_RESULT
Description Execute specific aFleX commands when an authentication result is
received.
NOTE: This event can only be used with old proxy. It is not supported with
new proxy.
Example Use the following example to handle authentication failure when the
request is not explicitly released:
when AUTH_RESULT {
HTTP::respond 403 content "Authentication Failed - Access
Denied"
}
87
Database Load-Balancing Events
The following database load-balancing (DBLB) events are available:
l DB_COMMAND
l DB_QUERY
l DB_RESPONSE
88
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
DB_COMMAND
Description Execute specific aFleX commands when an SQL command is sent by the
client.
89
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• reject
• return
• serverside
• encoding
• sha1
• snat
• string map
• substr
• switch
• use
• virtual
DB_QUERY
Description Execute specific aFleX commands when a full SQL query is received from
the client.
90
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• domain
• drop
• encoding
• event
• findstr
• getfield
• htonl
• htons
• if
• log
• md5
• members
• nexthop
• ntohl
• ntohs
• persist
• reject
• return
• serverside
• encoding
• sha1
• snat
• string map
• substr
• switch
• use
• virtual
Example Use the following example to separate database read queries from
write or other commands. The service-group sg-mysql-write includes
only the master MySQL server, where all write operations and other DB
91
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
pool sg-mysql-write
} else {
log "aflex got a read command: $ret"
pool sg-mysql-read }
}
when DB_COMMAND {
set ret [ DB::command ]
log "aflex script got command number: $ret"
pool sg-mysql-write
}
92
Diameter Load-Balancing Events
The following diameter load-balancing events are available:
l DIAMETER_ANSWER
l DIAMETER_ANSWER_SEND
l DIAMETER_REQUEST
l DIAMETER_REQUEST_SEND
93
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
DIAMETER_ANSWER
Description Execute specific aFleX commands when a complete Diameter answer
message is fully parsed.
94
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• nexthop
• ntohl
• ntohs
• persist
• reject
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
Example Use the following example to create a log entry whenever a Diameter
answer message is fully parsed.
when DIAMETER_ANSWER {
log "DIAMETER::cmd_code = [DIAMETER::cmd_code]"
}
DIAMETER_ANSWER_SEND
Description Execute specific aFleX commands immediately before a Diameter
answer is sent.
95
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
96
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• virtual
Example Use the following example to create a log entry immediately before a
Diameter answer is sent.
when DIAMETER_ANSWER_SEND {
log "DIAMETER::cmd_code = [DIAMETER::cmd_code]"
}
DIAMETER_REQUEST
Description Execute specific aFleX commands when a complete Diameter request
message is fully parsed.
97
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• htons
• if
• log
• md5
• members
• nexthop
• ntohl
• ntohs
• persist
• reject
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
Example Use the following example to create a log entry whenever a Diameter
request message is fully parsed.
when DIAMETER_REQUEST {
log "DIAMETER::cmd_code = [DIAMETER::cmd_code]"
}
DIAMETER_REQUEST_SEND
Description Execute specific aFleX commands immediately before a Diameter
request is sent.
98
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• DIAMETER::app_id
• DIAMETER::avp
• DIAMETER::cmd_code
• DIAMETER::length
• DIAMETER::version
99
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• sha1
• string map
• substr
• switch
• use
• virtual
Example To check the Origin-Realm value inside the incoming Diameter Request,
send a Diameter Response 3003 (Intended Realm is not recognized) back
to client if it is not "[Link]".
when DIAMETER_REQUEST {
set dropflag 0
if { !\([DIAMETER::avp [DIAMETER::avp get_ids 296] value]
equals "[Link]")}{
log " flag if Diameter AVP Origin-Realm is NOT [Link] "
set dropflag 1
}
}
when DIAMETER_ANSWER_SEND {
if { $dropflag } {
log "Remove server response code and return code 3003 to
client "
DIAMETER::avp [DIAMETER::avp get_ids 268] delete
DIAMETER::avp insert 268 3003 -M-
}
when DIAMETER_REQUEST_SEND {
log "DIAMETER::cmd_code = [DIAMETER::cmd_code]"
}
100
DNS Events
The following DNS events are available:
l DNS_REQUEST
l DNS_RESPONSE
101
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
DNS_REQUEST
Description Execute specific aFleX commands when DNS request packets arrive.
102
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• IP::category
• IP::reputation
103
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• ntohs
• persist
• reject
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
Example Use the following command to log the length of DNS queries received:
when DNS_REQUEST {
log "DNS Len: [DNS::len]"
}
104
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
DNS_RESPONSE
Description Execute specific aFleX commands when DNS reply packets arrive.
105
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• IP::reputation
106
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• persist
• reject
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
Example Use the following example to log the length of DNS reply packets
received.
when DNS_RESPONSE {
log "DNS Len: [DNS::len]"
}
107
Financial Information eXchange Events
The following Financial Information eXchange (FIX) events are available:
l FIX_REQUEST
l FIX_RESPONSE
108
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
FIX_REQUEST
Description Execute specific aFleX commands when a FIX request is received.
NOTE: This event is only valid on TCP-proxy and FIX virtual ports.
109
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• log
• md5
• members
• nexthop
• ntohl
• ntohs
• persist
• reject
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
when FIX_REQUEST {
if { [FIX::sender_compid] eq "CLIENT1" } {
pool fix_client_service_group
}
}
FIX_RESPONSE
Description Execute specific aFleX commands when a FIX response is received.
NOTE: This event is only valid on TCP-proxy and FIX virtual ports.
110
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
111
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• reject
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
Example Use the following example to log FIX information as specified when a
FIX response is received.
when FIX_RESPONSE {
log "[FIX::sender_compid] -> [FIX::target_compid]"
}
112
HTTP Events
The following HTTP events are available:
l HTTP_RESPONSE_DATA
l HTTP_RESPONSE_CONTINUE
l HTTP_RESPONSE
l HTTP_REQUEST_SEND
l HTTP_REQUEST_DATA
l HTTP_REQUEST
HTTP_REQUEST
Description Execute specific aFleX commands when a complete client request
header (method, URI, version, and all headers, not including the body)
is parsed.
113
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• AES::decrypt
• AES::encrypt
114
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• HTTP::is_keepalive
• HTTP::is_redirect
• HTTP::method
• HTTP::path
• HTTP::password
• HTTP::payload
• HTTP::query
• HTTP::redirect
• HTTP::release
• HTTP::request
• HTTP::request_num
• HTTP::respond
• HTTP::retry
• HTTP::status
• HTTP::stream
• HTTP::uri
• HTTP::username
• HTTP::version
115
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
116
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
117
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• b64encode
• clientside
• cpu usage
• domain
• drop
• encoding
• event
• findstr
• getfield
• htonl
• htons
• if
• log
• lwnode
• md5
• members
• nexthop
• ntohl
• ntohs
• persist
• pool
• reject
• return
• serverside
• session
• encoding
• sha1
• snat
• snatpool
• string map
• substr
118
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• switch
• use
• virtual
• whereis
Example Use the following example to redirect the client to HTTPS if a client
request URI contains the string "secure":
when HTTP_REQUEST {
if { [HTTP::uri] contains "secure" } {
HTTP::redirect "[Link]
}
}
Example Use this example to group traffic based on the WebDAV method in the
HTTP request header.
when HTTP_REQUEST {
if { not ([HTTP::method] equals "PROPFIND") } {
if { [IP::addr [IP::client_addr] equals
[Link]/24] } {
119
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
pool davwriters_service_group
}
} else {
pool davreaders_service_group
}
}
HTTP_REQUEST_DATA
Description Execute specific aFleX commands when an HTTP::collect command is
finished processing.
120
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• COMPRESS::enable
• COMPRESS::gzip
121
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• IP::category
• IP::client_addr
• IP::local_addr
• IP::protocol
• IP::remote_addr
• IP::reputation
• IP::server_addr
• IP::tos
• IP::ttl
• IP::version
122
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• SSL::renegotiate
• SSL::session invalidate
• SSL::sessionid
• SSL::verify_result
123
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• X509::subject_public_key
• X509::subject_public_key_RSA_bits
• X509::subject_public_key_type
• X509::text
• X509::verify_cert_error_string
• X509::version
• X509::whole
124
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• reject
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
• whereis
Example Use the following example to record a persist variable after data is
collected by the HTTP::collect command, then log the recorded
variable.
when HTTP_REQUEST_DATA {
set rpc_var [findstr [HTTP::payload] "Authorization:" 14
20]
persist uie $rpc_var
log "Persist UIE: $rpc_var"
HTTP::release
}
HTTP_REQUEST_SEND
Description Execute specific aFleX commands immediately before a request is sent
to a server. This is a server-side event.
125
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
126
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
127
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• X509::signature_algorithm
• X509::subject
• X509::subject_public_key
• X509::subject_public_key_RSA_bits
• X509::subject_public_key_type
• X509::text
• X509::verify_cert_error_string
• X509::version
• X509::whole
128
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• pool
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
• whereis
Example Use the following example to begin collecting TCP data immediately
before an HTTP request is sent to a server.
when HTTP_REQUEST_SEND {
HTTP::collect
}
HTTP_RESPONSE
Description Execute specific aFleX commands when all of the response status and
header lines from the server response are parsed.
129
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
130
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• HTTP::host
• HTTP::is_keepalive
• HTTP::is_redirect
• HTTP::method
• HTTP::query
• HTTP::redirect
• HTTP::release
• HTTP::request
• HTTP::request_num
• HTTP::respond
• HTTP::retry
• HTTP::status
• HTTP::stream
• HTTP::version
131
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• LID::exists
• LID::nat_pool
• LID::request_limit
• LID::request_rate_limit
• LID::type
132
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• domain
• drop
• encoding
• event
• findstr
• getfield
• htonl
• htons
• if
• log
• md5
• members
• nexthop
• ntohl
• ntohs
• persist
• reject
• return
• serverside
• session
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
• whereis
133
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
when HTTP_RESPONSE {
if { [HTTP::status] == 404 } {
HTTP::redirect "[Link]
}
}
HTTP_RESPONSE_CONTINUE
Description Execute specific aFleX commands whenever the system receives a 100
Continue response from the server.
Example Use the following example to create a log entry whenever a “100-
Continue” response is received from the server and the HTTP version is
other than 1.1:
when HTTP_RESPONSE_CONTINUE {
if { [HTTP::version] != 1.1 } {
log "Bad server: sent 100-Continue to non-1.1 client."
}
}
134
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
135
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
136
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• virtual
• whereis
137
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
HTTP_RESPONSE_DATA
Description Execute specific aFleX commands when an HTTP::collect command
finishes processing on the server side of a connection.
NOTE: This event is also triggered if the server closes the connection before
the HTTP:collect command finishes processing.
138
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
139
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• HTTP::release
• HTTP::request
• HTTP::request_num
• HTTP::respond
• HTTP::retry
• HTTP::status
• HTTP::stream
• HTTP::version
140
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
141
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• getfield
• htonl
• htons
• if
• log
• md5
• members
• nexthop
• ntohl
• ntohs
• persist
• reject
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
• whereis
142
ICAP Events
The following Internet Content Adaptation Protocol (ICAP) events are available:
l ICAP_REQUEST
l ICAP_RESPONSE
143
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
ICAP_REQUEST
Description Triggered when ICAP command is created but before being sent to ICAP
server.
Example Use the following command to define an ICAP URI to route traffic
through an ICAP server when an ICAP_REQUEST event is triggered:
when ICAP_REQUEST {
ICAP::uri icap://A10icap:1344/echo
}
ICAP_RESPONSE
Description Triggered after ICAP response has been processed but before result is
sent to the virtual server.
144
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• HTTP::host
• HTTP::is_redirect
• HTTP::method
• HTTP::path
• HTTP::redirect
• HTTP::request_num
• HTTP::respond
• HTTP::status
• HTTP::uri
Example Use the following command to log the ICAP response status and the
value of the 'ISTag' header when an ICAP_RESPONSE event is triggered:
when ICAP_RESPONSE {
log "ICAP response code is [ICAP::status]"
log "ISTag header value is [ICAP::header values ISTag]"
}
145
IP, TCP, and UDP Events
The following events related to IP, TCP and UDP traffic are available:
l CLIENT_ACCEPTED
l CLIENT_CLOSED
l CLIENT_DATA
l SERVER_CLOSED
l SERVER_CONNECTED
l SERVER_DATA
146
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
CLIENT_ACCEPTED
Description Execute specific aFleX commands when a client establishes a connection
with the ACOS device.
NOTE: For UDP (and only UDP), the CLIENT_ACCEPTED event is triggered on the
first UDP packet received.
147
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• DIAMETER::avp
• DIAMETER::cmd_code
• DIAMETER::length
• DIAMETER::version
148
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• LINK::vlan_id
Related Information
• TCP::remote_port
• TCP::respond
149
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• b64decode
• b64encode
• clientside
• cpu usage
• discard
• domain
• drop
• encoding
• event
• findstr
• getfield
• htonl
• htons
• if
• log
• lwnode
• md5
• members
• nexthop
• ntohl
• ntohs
• persist
• pool
• reject
• return
• serverside
• session
• encoding
• sha1
• sha256
• snat
150
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• snatpool
• string map
• substr
• switch
• use
• virtual
• when
• whereis
Example Use the following example to log the time whenever a connection is
established:
when CLIENT_ACCEPTED {
log "Client [IP::client_addr] connected at [clock format
[TIME::clock seconds] -format {%T}]"
}
CLIENT_CLOSED
Description Execute specific aFleX commands at the end of any client connection,
regardless of protocol.
151
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
152
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• LB::server
• LB::status
Related Information
• TCP::remote_port
• TCP::respond
153
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
154
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
• whereis
Example Use the following example to decrement the client IP counter by 1 each
time a client connection is closed. If all connections from the specified
client IP are closed, the counter is deleted.
when CLIENT_CLOSED {
set $client_ip [Link]
table set active_clients $client_ip 1
if { [table lookup active_clients $client_ip] != "" } {
table incr active_clients $client_ip -1
if {[table lookup active_clients $client_ip] <= 0 } {
table delete active_clients $client_ip}
}
}
CLIENT_DATA
Description Execute specific aFleX commands when new data is received from the
client while the connection is in a collect state.
NOTE: For UDP, the CLIENT_DATA event is automatically triggered for each UDP
packet received. IP fragmentation of a UDP packet is not supported for
the CLIENT_DATA event.
155
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• AES::encrypt
156
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• LID::request_limit
• LID::request_rate_limit
• LID::type
Related Information
• TCP::release
• TCP::remote_port
157
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• TCP::respond
158
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• reject
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
• whereis
Example Use the following example to select the service group “top_dns_
service_group” when a new client DNS request contains “TOP”:
when CLIENT_DATA {
if { [UDP::payload 50] contains "TOP" } {
pool top_dns_service_group
}
}
159
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
SERVER_CLOSED
Description Execute specific aFleX commands when the server-side connection
closes.
160
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• IP::local_addr
• IP::protocol
• IP::remote_addr
• IP::server_addr
• IP::tos
• IP::ttl
• IP::version
161
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• TCP::mss
• TCP::option
• TCP::rtt
• TCP::server_port
Related Information
• TCP::remote_port
• TCP::respond
162
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• members
• nexthop
• ntohl
• ntohs
• persist
• reject
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
• whereis
Example Use the following example to generate a log message containing the IP
address of the server whenever a server-side connection is closed:
when SERVER_CLOSED {
log "Server [IP::server_addr] has closed the connection"
}
SERVER_CONNECTED
Description Execute specific aFleX commands when a connection is established with
the server.
163
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• APPCLS::application
164
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• LID::request_rate_limit
• LID::type
Related Information
• TCP::remote_port
• TCP::respond
165
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• active_members
• b64decode
• b64encode
• clientside
• cpu usage
• domain
• drop
• encoding
• event
• findstr
• getfield
• htonl
• htons
• if
• log
• md5
• members
• nexthop
• ntohl
• ntohs
• persist
• reject
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
166
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• whereis
Example Use this example to create variables that include the IP addresses and
TCP ports of the client and the server when a server connection is
established:
when CLIENT_ACCEPTED {
set vip "[IP::local_addr]:[TCP::local_port]"
}
when SERVER_CONNECTED {
set client "[IP::client_addr]:[TCP::client_port]"
set node "[IP::server_addr]:[TCP::server_port]"
}
when CLIENT_CLOSED {
log "Client $client -> VIP: $vip -> Node: $node"
}
SERVER_DATA
Description Execute specific aFleX commands when new data is received from the
server while the connection is in a hold state.
NOTE: For UDP, the SERVER_DATA event is triggered for every packet. For TCP,
you need to issue a TCP::collect.
167
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
168
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
Related Information
• TCP::release
• TCP::remote_port
• TCP::respond
169
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• encoding
• event
• findstr
• getfield
• htonl
• htons
• if
• log
• md5
• members
• nexthop
• ntohl
• ntohs
• persist
• reject
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
• whereis
Example Use the following example to define the variable payload whenever
new data is received from the server while the connection is in a hold
state:
when SERVER_DATA {
log "TCP Payload: [TCP::payload]"
}
170
MQTT Events
The following MQTT events are available:
l MQTT_CLIENT_MESSAGE
l MQTT_CLIENT_MESSAGE_DATA
l MQTT_SERVER_MESSAGE
l MQTT_SERVER_MESSAGE_DATA
l MQTT_PUBLISH
l MQTT_SUBSCRIBE
MQTT_CLIENT_MESSAGE
Description Executes the specific aFleX scripts when a client sends an MQTT
message.
171
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• MQTT::keep_alive
• MQTT::length
• MQTT::packet_id
• MQTT::password
• MQTT::payload
• MQTT::payload_length
• MQTT::protocol_name
• MQTT::protocol_version
• MQTT::qos
• MQTT::replace
• MQTT::respond
• MQTT::retain_flag
• MQTT::return_code
• MQTT::session_present_flag
• MQTT::topic
• MQTT::type
• MQTT::username
• MQTT::will
MQTT_SERVER_MESSAGE_DATA
Description Triggered only when MQTT::collect finishes collecting under MQTT_
SERVER_MESSAGE
Example Use the following commands to collect and log MQTT message data
when a PUBLISH message is received from the server:
when MQTT_SERVER_MESSAGE {
MQTT::collect
}
when MQTT_SERVER_MESSAGE_DATA {
if { [MQTT::type] equals 8} {
172
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
MQTT_SERVER_MESSAGE
Description Executes the specific aFleX scripts when a server sends an MQTT
message.
173
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
174
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
MQTT_CLIENT_MESSAGE_DATA
Description Triggered only when MQTT::collect finishes collecting under MQTT_
CLIENT_MESSAGE
Example Use the following commands to collect and log MQTT message data
when a PUBLISH message is received from the client:
when MQTT_CLIENT_MESSAGE {
MQTT::collect
}
when MQTT_CLIENT_MESSAGE_DATA {
if { [MQTT::type] equals 8} {
log "payload in PUBLISH is [MQTT::payload]"
}
}
175
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• MQTT::retain_flag
• MQTT::return_code
• MQTT::return_code_list
• MQTT::session_present_flag
• MQTT::topic
• MQTT::type
• MQTT::username
• MQTT::will
MQTT_PUBLISH
Description Executes the specific aFleX scripts when a broker publishes an MQTT
PUBLISH message.
176
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• MQTT::protocol_version
• MQTT::qos
• MQTT::replace
• MQTT::respond
• MQTT::retain_flag
• MQTT::return_code
• MQTT::session_present_flag
• MQTT::topic
• MQTT::type
• MQTT::username
• MQTT::will
MQTT_SUBSCRIBE
Description Executes the specific aFleX scripts when a client subscribes to an MQTT
SUBSCRIBE message.
177
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• MQTT::payload
• MQTT::payload_length
• MQTT::protocol_name
• MQTT::protocol_version
• MQTT::qos
• MQTT::replace
• MQTT::respond
• MQTT::return_code
• MQTT::return_code_list
• MQTT::session_present_flag
• MQTT::topic
• MQTT::type
• MQTT::username
• MQTT::will
178
RAM Caching Events
The following RAM caching events are available:
l CACHE_REQUEST
l CACHE_RESPONSE
NOTE: These commands are supported on HTTP traffic (the original proxy),
but not supported on HTTP2 traffic (or the new proxy).
179
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
CACHE_REQUEST
Description Execute specific aFleX commands when a virtual server receives a
request for a cached object.
180
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• clientside
• cpu usage
• domain
• drop
• encoding
• event
• findstr
• getfield
• htonl
• htons
• if
• log
• md5
• members
• nexthop
• ntohl
• ntohs
• persist
• reject
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
Example Use the following example to revalidate a cached object from the server
if the age of the cache is greater than 60 seconds. A log message is also
created:
181
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
when CACHE_REQUEST {
if { [CACHE::age] > 60 } {
CACHE::expire
log "Expired Content: Age is greater than 60 seconds"
}
}
CACHE_RESPONSE
Description Execute specific aFleX commands immediately before sending a cache
response.
182
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• LID::type
183
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• use
• virtual
Example Use the following example to revalidate a cached object from the server
if the ::expired variable is set to 1. An expiration message is logged,
and then the ::expired variable is set to 0.
when CACHE_RESPONSE {
if { $::expired == 1 } {
CACHE::expire
log "cache expire"
table set expired 0 0
}
}
184
SIP Events
Session Initiation Protocol (SIP) events are supported for the following:
l SIP – Session Initiation Protocol over UDP
l SIP-TCP – SIP over TCP
l SIPS – Secure SIP over TLS
185
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
SIP_REQUEST
Description Execute specific aFleX commands when a full SIP request header is
received from the client.
186
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• if
• log
• md5
• members
• nexthop
• ntohl
• ntohs
• persist
• reject
• return
• serverside
• encoding
• sha1
• snat
• snatpool
• string map
• substr
• switch
• use
• virtual
187
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
Related Information
• TCP::remote_port
• TCP::respond
Example Use the following example to log the value of the Call-ID whenever an
SIP request header is received.
when SIP_REQUEST {
log "SIP Call_ID: [SIP::call_id]"
}
SIP_REQUEST_SEND
Description Execute specific aFleX commands when a SIP request is sent to the
server.
188
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• SIP::header
• SIP::method
• SIP::respond
• SIP::response
• SIP::to
• SIP::uri
• SIP::via
189
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
Related Information
• TCP::remote_port
• TCP::respond
190
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• UDP::local_port
• UDP::payload
• UDP::remote_port
• UDP::server_port
Example Use the following example to log the SIP method type whenever the
ACOS device sends a SIP request to the server.
when SIP_REQUEST_SEND {
log "SIP Method: [SIP::method]"
}
SIP_RESPONSE
Description Execute specific aFleX commands when a full SIP response is received
from the server.
191
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• domain
• drop
• encoding
• event
• findstr
• getfield
• htonl
• htons
• if
• log
• md5
• members
• nexthop
• ntohl
• ntohs
• persist
• reject
• return
• serverside
• encoding
• sha1
• snat
• snatpool
• string map
• substr
• switch
• use
• virtual
192
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• IP::local_addr
• IP::protocol
• IP::remote_addr
• IP::server_addr
• IP::tos
• IP::ttl
• IP::version
Related Information
• TCP::remote_port
• TCP::respond
Example Use the following example to log the SIP response code whenever a full
SIP response from the server is received.
when SIP_RESPONSE {
log "SIP Response Code: [SIP::response code]"
}
193
SMTP Events
The following Financial Information eXchange (FIX) events are available:
l SMTP_MAIL
l SMTP_EHLO
194
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
SMTP_MAIL
Description Triggers upon receiving MAIL FROM command from the client.
Example Use this example for routing SMTP traffic based on the sender's email
domain.
when SMTP_MAIL {
If {[SMTP::mail] equals [Link]} {
node [Link] 25
} else {
Node [Link] 25
}
}
SMTP_EHLO
Description Triggered when EHLO command arrives
Example Use this example for routing SMTP traffic based on the sender's email
domain.
when SMTP_EHLO {
SMTP::greet “VRFY”
}
195
SSL Events
The following SSL events are available:
l CLIENTSSL_CLIENTCERT
l CLIENTSSL_CLIENTHELLO
l CLIENTSSL_DATA
l CLIENTSSL_HANDSHAKE
l SERVERSSL_CLIENTHELLO_SEND
l SERVERSSL_DATA
l SERVERSSL_HANDSHAKE
l SERVERSSL_SERVERCERT
l SERVERSSL_SERVERHELLO
196
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
CLIENTSSL_CLIENTCERT
Description Execute specific aFleX commands when an SSL client certificate is
received.
197
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• SSL::verify_result
198
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• encoding
• event
• findstr
• getfield
• htonl
• htons
• if
• log
• md5
• members
• nexthop
• ntohl
• ntohs
• persist
• reject
• return
• serverside
• session
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
Example Use the following example to create a log and set the subject of the log
entry when an SSL client certificate is received.
when CLIENTSSL_CLIENTCERT {
log "X509 Subject: [X509::subject [SSL::cert 0]]"
}
199
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
CLIENTSSL_CLIENTHELLO
Description Execute specific aFleX command when an SSL Client Hello message is
received.
200
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• domain
• drop
• encoding
• event
• findstr
• getfield
• htonl
• htons
• if
• log
• md5
• members
• nexthop
• ntohl
• ntohs
• persist
• reject
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
Example Use the following example to begin collecting SSL application data when
an SSL Client Hello message is received:
when CLIENTSSL_CLIENTHELLO {
SSL::collect 100
}
201
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
when CLIENTSSL_DATA {
log "SSL Payload Length: [SSL::payload length]"
log "SSL Payload: [SSL::payload]"
SSL::release
}
CLIENTSSL_DATA
Description Execute specific aFleX commands when the ACOS device is in SSL collect
mode and receives an SSL application data message from a client.
202
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• TCP::local_port
• TCP::mss
• TCP::rtt
203
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• htonl
• htons
• if
• log
• md5
• members
• nexthop
• ntohl
• ntohs
• persist
• reject
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
Example Use this example to trigger SSL authentication and renegotiation when
the device enters SSL collect mode and receives SSL application data.
when CLIENT_ACCEPTED {
set renegotiate 1
set index 1
}
when CLIENTSSL_HANDSHAKE {
if { $renegotiate == 1 } {
log "SSL Handshake done - Index: $index"
incr index
set renegotiate 0
SSL::collect
} else {
204
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
CLIENTSSL_HANDSHAKE
Description Execute specific aFleX commands when an SSL handshake on the client
side is completed.
205
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• SSL::mode
• SSL::payload
• SSL::release
• SSL::renegotiate
• SSL::respond
• SSL::session invalidate
• SSL::sessionid
• SSL::sessionsecret
• SSL::template
• SSL::verify_result
206
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• X509::verify_cert_error_string
• X509::version
• X509::whole
207
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• substr
• switch
• use
• virtual
Example Use the following example to create a log and set the subject of the log
entry whenever an SSL handshake is completed on the client side.
when CLIENTSSL_HANDSHAKE {
log "X509 Subject: [X509::subject [SSL::cert 0]]"
}
SERVERSSL_CLIENTHELLO_SEND
Description Execute specific aFleX commands when the ACOS device sends a SSL
Client Hello message to the back-end server.
208
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
209
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• drop
• encoding
• event
• findstr
• getfield
• htonl
• htons
• if
• log
• md5
• members
• nexthop
• ntohl
• ntohs
• persist
• reject
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
Example Use the following example to begin collecting SSL application data
whenever an SSL Client Hello message is sent to the server.
when SERVERSSL_CLIENTHELLO_SEND {
SSL::collect
}
when SERVERSSL_DATA {
log "SSL Payload Length: [SSL::payload length]"
210
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
SERVERSSL_DATA
Description Execute specific aFleX commands when ACOS device is in SSL collect
mode and receives an SSL application data message from a back-end
server.
211
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• X509::extensions
• X509::hash
• X509::issuer
• X509::not_valid_after
• X509::not_valid_before
• X509::serial_number
• X509::signature_algorithm
• X509::subject
• X509::subject_public_key
• X509::subject_public_key_RSA_bits
• X509::subject_public_key_type
• X509::text
• X509::verify_cert_error_string
• X509::version
• X509::whole
212
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• md5
• members
• nexthop
• ntohl
• ntohs
• persist
• reject
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
Example Use the following example to log SSL data information and release the
collected data whenever the ACOS Device enters SSL collect mode and
receives data from the back-end server.
when SERVERSSL_HANDSHAKE {
SSL::collect 400
}
when SERVERSSL_DATA {
log "SSL Payload Length: [SSL::payload length]"
log "SSL Payload: [SSL::payload]"
SSL::payload replace 0 [SSL::payload length] "HTTP/1.1 200
OK\r\nContent-Length: 37\r\nContent-Type:
text/html;\r\n\r\n<html><head>Hello World!</head></html>"
SSL::release
}
213
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
SERVERSSL_HANDSHAKE
Description Execute specific aFleX commands when an SSL handshake on the server
side is completed.
214
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• X509::not_valid_after
• X509::not_valid_before
• X509::serial_number
• X509::signature_algorithm
• X509::subject
• X509::subject_public_key
• X509::subject_public_key_RSA_bits
• X509::subject_public_key_type
• X509::text
• X509::verify_cert_error_string
• X509::version
• X509::whole
215
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• ntohl
• ntohs
• persist
• reject
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
Example Use the following example to create a log and set the subject of the log
entry whenever an SSL handshake is completed on the server side.
when SERVERSSL_HANDSHAKE {
log "X509 Subject: [X509::subject [SSL::cert 0]]"
}
SERVERSSL_SERVERCERT
Description Triggered when the device receives an SSL certificate from the server
(after verification) .
216
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
SERVERSSL_SERVERHELLO
Description Execute specific aFleX command when an SSL Server Hello is received
from a back-end server.
217
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• APPCLS::application
218
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
• encoding
• event
• findstr
• getfield
• htonl
• htons
• if
• log
• md5
• members
• nexthop
• ntohl
• ntohs
• persist
• reject
• return
• serverside
• encoding
• sha1
• string map
• substr
• switch
• use
• virtual
Example Use the following example to enable SSL collect mode whenever an SSL
Server Hello message is received:
when SERVERSSL_SERVERHELLO {
SSL::collect
}
when SERVERSSL_DATA {
log "SSL Payload Length: [SSL::payload length]"
log "SSL Payload: [SSL::payload]"
219
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Events
SSL::release
}
220
aFleX Commands
l Global Commands
l Global Variable Commands
l AAM Commands
l Application Firewall Commands
l AES Commands
l Category Commands
l Class List Commands
l Compression Commands
l Compression Commands
l Database Load-Balancing Commands
l Diameter Load-Balancing Commands
l DNS Commands
l Financial Information eXchange Commands
l HTTP Commands
l ICAP Commands
l IP Commands
l Limit ID Commands
l Link Commands
l Load-balancing Commands
l MQTT Commands
l Policy-Based SLB Commands
l RADIUS Message Load-balancing Commands
l RAM Caching Commands
l Resolve Commands
221
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
l SIP Commands
l SMTP Commands
l SSL Commands
l Statistics Commands
l Table Commands
l TCP Commands
l Template Commands
l Time Commands
l UDP Commands
l URI Commands
l URL Commands
l X509 Commands
l Deprecated and Disabled Commands
222
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Overview
aFleX commands can perform the following types of operations:
l Global – Performs actions such as selecting a pool (SLB service group) or node
(server).
Query commands:
l IP packet header query – Returns information from the IP header.
l IP, TCP, or UDP packet data query – Returns information from the payload.
l HTTP packet header or content query – Returns information from the HTTP
header or payload.
l Header and content manipulation:
l HTTP cookie manipulation – Changes cookies.
l TCP header and content manipulation – Changes TCP headers or content.
l HTTP header and content manipulation – Changes HTTP headers or content.
l SSL and X.509 query – Returns information from or about certificates.
l Deep packet inspection – Returns strings from packets.
For information about other script components, see aFleX Script Components.
223
Global Commands
The following global aFleX commands are available:
l active_members
l b64decode
l b64encode
l clientside
l cpu usage
l domain
l drop
l encoding
l event
l findstr
l getfield
l htonl
l htons
l log
l lwnode
l md5
l members
l nexthop
l lwnode
l ntohl
l ntohs
l persist
l pool
224
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
l reject
l return
l serverside
l session
l encoding
l sha1
l snat
l snatpool
l string map
l substr
l switch
l use
l virtual
l when
l whereis
active_members
Description This command returns either the number of active members in a service
group or pool or a listing. When the optional list parameter is not used,
then the default behavior outputs the number of active members.
225
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
when HTTP_REQUEST {
if { [active_members example_service_group] <= 3 } {
pool service_group_backup
}
}
Example The following configuration logs the list of currently active members in
the service_group_http service group when an HTTP request is
received:
when HTTP_REQUEST {
log "The service group http active member list is [active_
members list service_group_http]"
}
Output:
[AFLEX]:af: The service group http active member list is
{[Link] 80}
Valid Events
All
b64decode
Description This command returns a specified string that was decoded from base-
64. If there is an error, it will return NULL.
Example Use this example to decode a base-64 encoded cookie from the HTTP
request:
when HTTP_REQUEST {
set encoded_cookie [HTTP::cookie "EncodedCookie"]
set decoded_cookie [b64decode $encoded_cookie]
HTTP::cookie insert name "ClearCookie" value $decoded_
cookie
}
Valid Events
226
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
All
b64encode
Description This command returns a specified encoded base-64 string when used. If
there is an error, it will return NULL.
Example Use this example to Base64-encode a cookie from the HTTP request:
when HTTP_REQUEST {
set decoded_cookie [HTTP::cookie "ClearCookie"]
set encoded_cookie [b64encode $decoded_cookie]
HTTP::cookie insert name "EncodedCookie" value $encoded_
cookie
}
Valid Events
All
b64urldecode
Description This command returns a specified string that was decoded from base-
64URL. It handles URL-safe characters and optional padding. If there is
an error, it will return NULL.
Example Use this example to decode a Base64 URL-encoded string inside an HTTP
request:
227
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
when HTTP_REQUEST {
set encoded_data "SGVsbG8tV29ybGRf" ;# URL-safe Base64
for "Hello-World_"
set decoded_data [b64urldecode $encoded_data]
log "Decoded result: $decoded_data"
}
b64urlencode
Description This command returns a specified base-64URL-encoded string. If there is
an error, it will return NULL.
Example Use this example to encode a string for safe transmission in URLs or
tokens:
when HTTP_REQUEST {
set plain_text "Hello-World_"
set encoded_text [b64urlencode $plain_text]
log "Encoded result: $encoded_text"
}
client_addr
Description This command retrieves the IP address of the client that initiated the
connection. It is used to perform operations based on the client's
address, such as filtering or redirecting traffic.
Example Use this example to log or redirect traffic based on client IP address:
228
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
when HTTP_REQUEST {
if {[client_addr] eq "[Link]"} {
HTTP::redirect "[Link]
} else {
log "Client IP: [client_addr]"
}
}
Valid Events
All
client_port
Description This command retrieves the port number of the client making the
connection. It is used to inspect or filter traffic based on the client's
source port.
Example Use this example to log the source port of a client making an HTTP
request:
when HTTP_REQUEST {
set src_port [client_port]
log "Client is connecting from port: $src_port"
}
Valid Events
All
229
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
clientside
Description Using this command will take specified aFleX commands to be put in
assessment under the client-side context. It will not affect aFleX
commands that are already under the client-side context being
assessed.
Example The following example uses the clientside command to retrieve the
client-side IP address after the server connection is established. If the
client's IP address matches [Link], the connection is discarded:
when SERVER_CONNECTED {
if { [IP::addr [clientside {IP::remote_addr}] equals
[Link].0] } {
discard
}
}
Valid Events
All
cpu usage
Description This command will return the average CPU load for an interval based on
the defined time. The average is a moving average that is exponentially
weighted over an interval.
Example The following example uses the cpu command to check the average CPU
load over the last 15 seconds:
when HTTP_REQUEST {
if { [cpu usage 15secs] <= 60} {
example_service_group
230
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
} else {
HTTP::redirect "[Link]
}
}
Valid Events
All
discard
Description Depending on the event, this command will discard the connection or
current packet. This must be conditionally associated with an if
statement and essentially functions the same as the drop command.
Syntax discard
Example Use the following example to discard the connection if the client's IP
address matches [Link]:
when SERVER_CONNECTED {
if { [IP::addr [IP::remote_addr] equals [Link]] } {
discard
}
}
Valid Events
All
dnat
Description Enables destination NAT on the current connection by modifying the
destination IP address. Commonly used to redirect traffic to internal
servers.
231
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use this example to change the destination IP address for an incoming
HTTP request to [Link]:
when HTTP_REQUEST {
dnat [Link]
}
Valid Events
CLIENT_ACCEPTED
HTTP_REQUEST
domain
Description This command returns a specified string as a dotted domain name. In
addition, the last <count> portions of a domain name will be returned.
Valid Events
All
drop
Description Depending on the event, this command will drop the connection or
current packet. This must be conditionally associated with an if
statement and essentially functions the same as the discard command.
Syntax drop
232
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use the following example to drop the connection if the client IP
address is [Link]:
when CLIENT_ACCEPTED {
if { [IP::addr [IP::client_addr] equals [Link]] } {
drop
}
}
Valid Events
All
encoding
Description This command takes a character encoded payload and converts it to the
specified encoding format.
Valid Events
All
esha256
Description Signing ES256 (ECDSA using P-256 and SHA-256) signature.
Example Use the following example to generate and log an ECDSA SHA-256
signature for a string when a client sends an HTTP request:
233
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
when HTTP_REQUEST {
set msg "data to sign"
set signature [hsha256 "$msg" [Link]]
}
Valid Events
All
event
Description This command will abandon the review of specified aFleX events, or
everything on the connection depending on the parameters chosen,
while the aFlex script continues to run.
Example Use the following example to disable the HTTP_REQUEST event when
the client IP address is [Link]:
when CLIENT_ACCEPTED {
if { [IP::addr [IP::client_addr] equals [Link]] } {
event HTTP_REQUEST disable
}
}
when HTTP_REQUEST {
log "There is a HTTP Request from: [IP::client_addr]"
}
Valid Events
All
findstr
Description This command is used to locate a string <search_string> within another
string <string>, where the result is the offset string specified from the
234
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example The following example checks if the URI contains "type=" and returns
"cgi" after skipping 5 characters, then directs traffic to different pools
based on the result:
when HTTP_REQUEST {
if { [findstr [HTTP::uri] "type=" 5 "&"] eq "cgi" } {
pool service_group_dynamic
} else {
pool example_service_group
}
}
Valid Events
All
forward
Description Sends the current packet or connection to its next destination based on
current routing or SLB decisions. This command is used to manually
resume or continue forwarding after a conditional check or custom
logic in the script.
Syntax forward
Example Use this example to forward the request to node [Link] if certain
conditions are met:
235
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
when HTTP_REQUEST {
if { [HTTP::uri] starts_with "/api" } {
forward node [Link]
}
}
Valid Events
All
getfield
Description This command provides the corresponding string from a specified field
through the <string> or <split> attributes.
Example Use the example to show the extraction of the hostname from the host
header.
when HTTP_REQUEST {
[getfield [HTTP::host] ":" 1]
}
Example Use the second example to show how to redirect request for
[Link] to [Link]
when HTTP_REQUEST {
if { [HTTP::host] contains "[Link]" } {
HTTP::redirect [Link] [HTTP::host]
".[Link]" 1].[Link][HTTP::uri]
}
}
Valid Events
All
236
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
hsha256
Description Generates a digital signature using HMAC (Hash-based Message
Authentication Code) combined with the SHA-256 hashing algorithm.
Example Use the following example to generate and log the HMAC-SHA256 hash
of the data using a secret key when a client sends an HTTP request:
when HTTP_REQUEST {
set msg "data to sign"
set secret "password"
set signature [hsha256 "$msg" $secret]
Valid Events
All
htonl
Description This command converts a hosts’ byte order of an unsigned integer to
network byte order.
Example The following example converts the integer 12348765 from host byte
order to network byte order:
when HTTP_REQUEST {
set hostlong 12348765
set netlong [htonl $hostlong]
}
Valid Events
All
237
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
htons
Description This command converts a hosts’ byte order of an unsigned short
integer to network byte order.
Example The following example converts the integer 1423 from host byte order
to network byte order (16-bit) using the htons command:
when HTTP_REQUEST {
set hostshort 1423
set netshort [htons $hostshort]
}
Valid Events
All
if
Description Use this command to query for a true or false answer, and take action
based upon that answer. The elseif and else commands can be added
after an if command.
238
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use this example for routing HTTP requests to different service groups
based on the file extension in the URI:
when HTTP_REQUEST {
if { [HTTP::uri] ends_with ".html" } {
pool service_group_static
} elseif { [HTTP::uri] ends_with ".asp" } {
pool service_group_dynamic
}
}
Valid Events
All
ip_protocol
Description Retrieves the IP protocol value from the current packet. Can be used for
conditional logic within aFleX scripts to match specific protocols (e.g.,
TCP, UDP, ICMP). Must be conditionally associated with an if statement.
Example Use this example to check if the IP protocol is UDP (protocol number
17), and take an action:
when CLIENT_DATA {
if { [ip_protocol] == 17 } {
log "UDP traffic detected"
}
}
Valid Events
239
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
All
ip_tos
Description Retrieves the Type of Service (ToS) value from the IP header of the
packet. Often used for traffic classification or prioritization.
Example Use this example to log traffic with a specific ToS value:
when CLIENT_DATA {
if { [ip_tos] == 184 } {
log "High-priority traffic detected"
}
}
Valid Events
All
ip_ttl
Description Retrieves the Time to Live (TTL) value from the IP header of the packet.
TTL helps determine how many hops a packet can traverse before being
discarded.
Example Use this example to drop packets with TTL less than or equal to 1:
240
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
when CLIENT_DATA {
if { [ip_ttl] <= 1 } {
drop
log "Dropped packet with TTL <= 1"
}
}
Valid Events
All
local_addr
Valid Events
All
log
Description This command creates and logs a specified message to the Syslog utility
through a variable expansion on messages as prescribed for the HTTP
profile Header Insert setting. Use "local0" to "local7" as the value for
facility (Note: only "local0" is supported). For <level>, the number value
from 0 to 7 can be used, or its corresponding level string, "EMERG",
"ALERT", "CRIT", "ERR", "WARNING", "NOTICE", "INFO", and "DEBUG".
241
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
NOTE:
l Use the log command carefully, as it can produce an enormous
amount of input.
l When using the Syslog facility, the log is limited to 1024 bytes per
request. Longer strings will be truncated.
l Regardless of level, the aFlex log command messages are rate limited
as a class. Thus, subsequent messages within the rate-limit period
may be curbed despite textual differences. Duplicate messages in
Syslog are suppressed.
Example The following example logs a message using the default facility local0
and default level INFO (6):
log "The log message is from facility local0 by default and
level INFO (6) by default"
Example The following example logs a message using facility local2 and default
level INFO (6):
log local2."The log message is from facility local2 and level
INFO (6) by default"
Example The following example logs a message using facility local2 and severity
level 0 (EMERG):
log local2.0 "This log massage is from facility local2 and
level 0 (EMERG)"
Example The following example logs a message using facility local2 and severity
level DEBUG (7):
log [Link] "This log massage is from facility local2 and
level DEBUG (7)"
NOTE: In ACOS 4.0.1, aFlex log entries are recognized so log messages for aFlex
events will be linked with the aFlex script where they occurred.
242
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example In ACOS 4.0.1 and higher, with the application of three aFleX scripts
(af1, af2, and af3) to its virtual port using the show log output for an
SLB, virtual server will display the following:
ACOS(config)#show log
Aug 05 2014 11:58:14 Info [AFLEX]:af3:HTTP status : 200
Aug 05 2014 11:58:14 Info [AFLEX]:af3:HTTP_RESPONSE event
Aug 05 2014 11:58:14 Info [AFLEX]:af2:Another http request
cmd!
Aug 05 2014 11:58:14 Info [AFLEX]:af1:This is http_request_
1
Prior to ACOS 4.0.1, the application of the three aFlex scripts would
have produced the following show log output:
ACOS(config)#show log
Aug 14 2014 10:11:07 Info [AFLEX]:af1+af2+af3:HTTP status :
200
Aug 14 2014 10:11:07 Info [AFLEX]:af1+af2+af3:HTTP_RESPONSE
event
Aug 14 2014 10:11:07 Info [AFLEX]:af1+af2+af3:Another http
request cmd!
Aug 14 2014 10:11:07 Info [AFLEX]:af1+af2+af3:This is http_
request_1
Valid Events
All
lwnode
Description This command forces the specified server node to be used directly,
bypassing any load-balancing. The difference between this command
and the node command is that lwnode can be referred to an entity that
is not a service-group member or a defined part of the real server
configuration.
243
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
NOTE: When using the lwnode command, a source NAT pool must be applied.
NOTE: Nodes selected by using this command do not have connection limiting
and connection rate limiting applied.
Example Use this example to route incoming HTTP requests to different origin
servers based on the URI path:
when HTTP_REQUEST {
switch -glob [string tolower [HTTP::uri]] {
"/static1/*" { lwnode [Link] }
"/static2/*" { lwnode [Link] }
"/static3/*" { lwnode [Link] }
default { lwnode [Link] 8080 }
}
}
Valid Events c
md5
Description This command provides the RSA MD5 Message Digest Algorithm
message digest of the specified string.
Example The following example generates the MD5 hash of a string and converts
it to a readable ASCII format:
when CLIENT_ACCEPTED {
set md5_binary [md5 "1234509876"]
binary scan $md5_binary H* md5_ascii
log "MD5: $md5_ascii"
}
Valid Events
All
244
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
members
Description This command counts or lists all the service group members.
Example Use the following example to list members. If this option is removed,
the output is the member count.
when CLIENT_ACCEPTED {
log "Here are the Total Member(s): [members list example_
service_group]"
}
Valid Events
All
nexthop
Description This command will set the next hop for a connection.
For the events listed, using this command overwrite the default reverse
next-hop IP address:
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• SERVER_CONNECTED
• SERVER_DATA
For other cases, use of this command will overwrite the forward next-
hop IP address.
245
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
when CLIENT_ACCEPTED {
if { [IP::addr [IP::client_addr] equals [Link]/24] }
{
nexthop [Link]
log "Nexthop: [Link]"
} else {
log “Nexthop: default ([Link])”
}
}
Valid Events
All
node
Description This command forces the specified server node that is comprised of an
IP address and a port number to be used directly, and bypass any load-
balancing.
NOTE: This command supports old SSL (N5) and new SSL (QAT, new N5, and
Software TLS1.3).
NOTE:
l Use of the node command requires the configuration of a real server
(node) and service port as a member of a service group.
l Nodes selected through this command do not have connection
limiting and connection rate limiting applied to them.
Example Use the following example to send an HTTP request to a specific node
with the IP address [Link] on port 80 for a URI ending with
'.png'.
when HTTP_REQUEST {
if { [HTTP::uri] ends_with ".png" } {
246
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
node [Link] 80
}
}
ntohl
Description This command converts a network byte order’s unsigned integer to a
host byte order.
Valid Events
All
ntohs
Description This command converts a network byte order’s unsigned short integer
to a host byte order.
Example The following example converts the network-ordered short integer 1243
to host byte order:
when HTTP_REQUEST {
set netshort 1243
set hostshort [ntohs $netshort]
}
Valid Events
247
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
All
persist
Description This command sets client persistence based on the value chosen.
Use of this command sets the key for an entry on the persistence table.
This maps the client to an SLB resource (real server, real server port, or
service group). If the persistence table contains the specified key, the
ACOS device uses the SLB resource that key is mapped to in the table.
Otherwise, the ACOS device will use SLB to select a resource and create
a corresponding persistence table entry. The uie option, “Universal
Inspection Engine”, indicates that persistence can be set based on any
key.
Use the following syntax to add an entry to the persistence table. This
command differs from the command above because it does not first
check the persistence table for an existing entry for the key. The
persist add form of the command is useful for setting persistence
based on data that is set on the server and is therefore first observed
by the ACOS device in the server response, rather than in the client
request.
persist add uie <key> [<timeout>]
248
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• all – This parameter returns all the values listed below. (If not
specified, and none of the other options are specified, the
command interpretation is equivalent to specifying all.
• node – This parameter will return the real server IP address.
• port – This parameter will return the real service port number.
• pool – This parameter will return the pool (service group) name.
Use the following syntax to delete the persistence table entry for the
specified key.
persist delete uie <key>
Syntax <key>
The use of the <key> specifies the data upon which the persistence is
based. It can be specified with one of the following options:
<specified-value>
Use persist to the same real server and port if traffic contains the
specified key value and is sent to the same virtual port.
{<specified-value> [any virtual | any service | any pool]
[pool <pool-name>]}
any virtual Use for persistence to the same real server and port
if traffic contains the specified key value and is sent
to the same virtual port and service group (pool).
any service Use for persistence to the same real server if traffic
contains the specified key value and is sent to the
249
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
NOTE:
l Server template limits are applied for both service-group and server
selection. Commands that call for server selection such as “node”,
“pool”, and “persist” will enforce server template limits on the
selected server. As a result, new connections that match a persist uie
entry may find themselves unable to use the rport and a default
server selection will occur instead. To prevent default server
selection, use the no def-selection-if-pref-failed command for the
vport.
l If the length of the persist UIE key in aFlex exceeds the internal limit
of 63 characters, aFlex truncates the key to an appropriate length for
use.
l To show the persistent sessions managed by this aFleX command,
use the following command in the CLI: show session persist uie.
Example Use the following example script to provide persistence on a VIP on any
port.
when HTTP_REQUEST {
set IP [IP::client_addr]
set p [persist lookup uie { $IP any virtual } all]
if { $p ne "" } {
log " UIE located ([lindex $p 0] [lindex $p 1] [lindex
$p 2])"
node [lindex $p 1] [lindex $p 2]
}
}
when HTTP_RESPONSE {
set IP [IP::client_addr]
250
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use the following example script to provide the same persistence for a
client IP address accessing one VIP and port:
when HTTP_REQUEST {
set IP [IP::client_addr]
persist uie $IP
}
when HTTP_RESPONSE {
set IP [IP::client_addr]
persist add uie $IP 1800
}
Example Use the following example script to provide the same persistence for a
client IP address accessing any VIP and any port:
when HTTP_REQUEST {
set IP [IP::client_addr]
set p [persist lookup uie { $IP any service } all]
if { $p ne "" } {
log " UIE located([lindex $p 0] [lindex $p 1] [lindex
$p 2])"
node [lindex $p 1] [lindex $p 2]
}
}
when HTTP_RESPONSE {
set IP [IP::client_addr]
persist add uie { $IP any service } 1800
}
Valid Events
All.
251
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
pool
Description This command will cause the system to load balance traffic to the
specified pool or pool member. This statement must have an if
statement conditionally associated with it.
This command acts upon the service groups (pools) located in the
partition that contains the aFleX policy.
NOTE: This command supports old SSL (N5) and new SSL (QAT, new N5, and
Software TLS1.3).
NOTE:
l Pool/member may be selected conditionally. If multiple conditions
match, the last match determines the pool/member to which this
traffic is load balanced.
l Server template limits are applied for both service-group and server
selection. Commands that call for server selection such as node, pool,
and persist will enforce server template limits on the selected
server. As a result, new connections that match a persist uie entry
may be unable to use the rport and a default server selection will
occur instead. To prevent a default server selection, use the no def-
selection-if-pref-failed command for the vport.
Valid Events
• CLIENT_ACCEPTED
252
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• CLIENT_DATA
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• LB_FAILED
Events that do not generate an error, but are likely not valid for this
command:
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
redirect
Description Redirects traffic to a new destination IP address or virtual port for all
virtual ports in the configuration.
Valid Events
All
reject
Description This command will cause the connection to be rejected, and return a
reset as appropriate for the protocol.
253
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Syntax reject
Example The following example rejects the connection if the client IP address
matches [Link]:
when CLIENT_ACCEPTED {
if { [IP::addr [IP::client_addr] equals [Link]] } {
reject
}
}
Valid Events
All
remote_addr
Description Associates the remote address (IP) with all virtual ports. This command
is often used to match the source IP address across all virtual port
configurations.
Valid Events
All
rsha256
Description Signing or verifying RS256 signature.
254
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use the following example to generate and log an RSA SHA-256
signature for a string when a client sends an HTTP request:
255
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
when HTTP_REQUEST {
set msg "data to sign"
# Generate RSA SHA-256 signature using private key
set signature [rsha256 sign $msg [Link]]
# Verify using certificate
if { not [rsha256 verify $msg cert [Link] $signature] }
{
log "signature verify failed"
}
# Define base64url-encoded public key components
set n_b64url "ALsmiIFNcbzhSedzFUW1dn2yiurXgnPZF17PeL_
zPDVkHQirealmWDIf6Rmt0lvz0E\
amdFrwHLtKqAdrgg9w7fq1Ws_
lK0zFefMXsVI7OA4TXYhQYADnOe0wkUEKCngj7dfej\
FZ-06iu6Hrza7U1Nb-CSqM42zDCwvdvUY2K6Vxx"
set e_b64url "AQAB"
# Decode the base64url public key components
set n [b64urldecode $n_b64url]
set e [b64urldecode $e_b64url]
# Verify using public key
if { not [rsha256 verify $msg public-key $n $e $signature]
} {
log "signature verify failed"
}
# Verify using JWK
if { not [rsha256 verify $msg jwk [Link] $signature] } {
log "signature verify failed"
}
}
Valid Events
All
256
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
return
Description This command terminates execution of an aFleX event and would
optionally return the result of the evaluating expression.
Example Use of the following example shows that the foreach loop is broken by
the return command if the string “X-ClientIP” is found in the HTTP
header.
when HTTP_REQUEST {
foreach header [HTTP::header names] {
if { [HTTP::header exists "X-ClientIP"] } {
return
} else {
HTTP::header insert X-Forwarded-For [IP::client_
addr]
}
}
}
Valid Events
All
server_addr
Description Returns the destination server IP address associated with the current
connection. This command is useful for retrieving or matching the
backend server IP during a transaction.
Valid Events
257
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
All
server_port
Description Returns the destination server port associated with the current
connection. It can be used in logic to identify traffic targeting specific
backend services by port.
Valid Events
All
serverside
Description This command will cause the specified aFleX command or commands to
be evaluated under the server-side context. This command has no effect
if the aFleX policy is already being evaluated under the server-side
context.
Example The following example drops the connection if the remote IP address of
the server matches [Link]:
when CLIENT_ACCEPTED {
if {[IP::addr [serverside {IP::remote_addr}] equals
[Link]] } {
drop
}
}
258
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
All
session
Description This command manages SSL sessions.
Use the following syntax to search the SSL table for information about
the specified key:
session lookup ssl <key>
Example Use the following example to store client certificate against the SSL
session ID during the handshake phase and then retrieve it:
when CLIENTSSL_HANDSHAKE {
set cert1 [SSL::cert 0]
session add ssl [SSL::sessionid] $cert1 300
}
when HTTP_REQUEST {
set cert2 [session lookup ssl [SSL::sessionid]]
}
Valid Events
• CLIENT_ACCEPTED
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
259
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• HTTP_REQUEST
• HTTP_RESPONSE
encoding
Description This command will set the character encoding for data payloads.
Example Use the following example to convert a byte sequence from the EUC-JP
encoding (a Japanese character encoding) into Tcl's internal Unicode
string format (UTF-8 by default).
when HTTP_RESPONSE {
if { [HTTP::header "Content-Type"] contains "Shift_JIS" } {
set s [encoding convertfrom euc-jp "\xA4\xCF"]
HTTP::collect
}
}
when HTTP_RESPONSE_DATA {
set hoge [HTTP::payload length]
set payload [encoding convertfrom $encode [HTTP::payload]]
regsub -all "abc" $payload "xyz" newdata
set newdata3 [encoding convertto $encode $newdata]
HTTP::payload replace 0 $hoge $newdata3
HTTP::release
}
Valid Events
All
sha1
Description This command will return the Secure Hash Algorithm version 1.0 (SHA1)
message digest of the specified string.
260
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use this example to hash a user-supplied value and log the result:
when HTTP_REQUEST {
set input "example_input"
set hash [sha1 $input]
log "SHA-1 hash of input: $hash"
}
Valid Events
All
sha256
Description Generates a digital signature using SHA-256 (Secure Hash Algorithm
version 2.0) hashing algorithm.
Example Use the following example to generate and log the SHA-256 hash of a
given string when a client connects:
when CLIENT_ACCEPTED {
log "[sha256 "123456789"]"
}
Valid Events
All
snat
Description This command will assign, select or disable source NAT.
261
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Usage Use of this command will assign the specified NAT address (<addr>) to
the server-side connection. The command replaces the reverse
destination address of the connection with the specified IP address.
Example The following example script will apply the specified source NAT
address for clients in the [Link]/24 subnet:
when CLIENT_ACCEPTED {
if { [IP::addr [IP::client_addr] equals [Link]/24] }
{
snat [Link]
} else {
snat [Link]
}
}
Valid Events
• CLIENT_ACCEPTED
• LB_SELECTED
• SIP_REQUEST
• SIP_RESPONSE
• DB_COMMAND
• DB_QUERY
• HTTP_REQUEST
snatpool
Description This command will use the specified pool of IP addresses as translation
addresses to create a SNAT. It uses the specified NAT pool instead of
the NAT pool that is already bound to the virtual port in the ACOS
configuration.
262
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
snatpool none
NOTE:
l A NAT pool must already be bound to a virtual port in the ACOS
configuration. This is the virtual port’s default NAT pool.
l The IP type, IPv4 or IPv6 of the pool must be the same as the IP type
of the real servers.
Example The following example assigns the source NAT pool based on the
client's IP address. If the client’s IP is [Link], it uses the snat-
internal pool; otherwise, it uses the snat-external pool:
when CLIENT_ACCEPTED {
if { [IP::addr [IP::client_addr] equals [Link]] } {
snatpool snat-internal
} else {
snatpool snat-external
}
}
Valid Events
• CLIENT_ACCEPTED
• HTTP_REQUEST
• LB_SELECTED
• SIP_REQUEST
• SIP_RESPONSE
string map
Description This command will map the value of the second string to the value of
the first string. Each instance of the <string1> will be replaced with
<string2>.
263
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example This example illustrates that when an HTTP request comes in and has
"/abc" in its uri, it will be changed to "/def" when it is sent to the
backend server.
when HTTP_REQUEST {
if {[HTTP::uri] contains "static"} {
HTTP::uri [string map {"/static" "/images"} [HTTP::uri]]
}
}
Valid Events
All
substr
Description This command returns a sub-string named <string>, based on the
values of the <skip_count> and <terminator> arguments.
264
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
This command is the same as the Tcl string range command except that
the value of the <terminator> argument may either be a character or a
count.
when HTTP_REQUEST {
set uri [substr $uri 1 "?"]
log local0. "Uri Part = $uri"
}
log "[substr "abcdefghijklm" 2 "x"]"
log "[substr "abcdefghijklm" 2 "gh"]"
log "[substr "abcdefghijklm" 2 4]"
log "[substr "abcdefghijklm" 2 20]"
log "[substr "abcdefghijklm" 2 0]"
Valid Events
All
switch
Description This is a built-in Tcl command that evaluates one of several scripts,
depending on a given value.
This command matches its string argument against each of the pattern
arguments in order. As soon as the command finds a pattern that
matches the string, it evaluates the following body argument by
passing it recursively to the Tcl interpreter and returns the result of
that evaluation. If the last pattern argument is "default", then it
matches anything. When no pattern argument matches string and no
265
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
If matching string to the patterns, use the following option for glob-
style matching which is the same as implementation by the string
match command.
-glob
This will mark the end of options. The argument following this one will
be treated as string even if it starts with a "-".
--
There are two syntaxes provided for the pattern and body arguments.
The first syntax uses a separate argument for each of the patterns and
commands. It is normally easier to use if substitutions are desired on
some of the patterns or commands.
The second form will place all of the patterns and commands together
into a single argument. The argument must have a proper list structure
with elements of the list being the patterns and commands. The second
form facilitates construction of multi-line commands since the braces
around the whole list make it unnecessary to include a backslash at the
end of each line. Since the second form has its pattern arguments in
braces, no command or variable substitutions are performed on them;
this differentiates the second form from the first form in some
situations.
When a body is specified as "-", it means the body’s next pattern
should be used as the body for this pattern. Although, note that when
266
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
the next pattern also has a body of "-", then the body after that is used,
and so forth. Doing this allows sharing of a single body among several
patterns.
NOTE: If the result of the switch evaluation is invalid, the script stops but no
compilation error will be displayed. Make sure that all possible
outcomes are valid, or consider using the if ... elseif syntax instead
of switch.
267
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
default
{format 3}
}
Example The use of the following example sends traffic with host header
"[Link]" to pool www, host header "[Link]",
which will cause header manipulation and URI rewriting to take place
first, and requests with any other host header will be discarded:
when HTTP_REQUEST {
switch -glob [string tolower [HTTP::uri]] {
"/images*" -
"/static*" { pool service_group_static }
"/blog*" { pool service_group_example }
"/internal*" { pool service_group_internal }
default { pool service_group_dynamic }
}
}
Valid Events
All
table
Description Provides a mechanism to store and retrieve key-value pairs in memory.
Useful for caching, session tracking, or custom logic flows.
Valid Events
All
268
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
use
Description This command is used to deal with backwards compatibility. It must be
paired with the node, pool or other ACOS command. It is recommended
that use of these commands be done directly rather than the use
command.
Example The following example shows the incorrect usage of use pool, which is
not a valid syntax in aFleX:
when HTTP_REQUEST {
if { [HTTP::uri] ends_with ".html" } {
use pool service_group_static
} elseif { [HTTP::uri] ends_with ".asp" } {
use pool service_group_dynamic
}
}
The pool command should be used directly without the use keyword.
Valid Events
All
269
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
utc_to_numeric_date
Description Converts a time value in UTC format (used in SAML tokens) into a
NumericDate format, which is commonly used in JWT (JSON Web
Token).
Example Use the following example to convert a UTC timestamp into JWT-
compatible NumericDate format and log it:
when CLIENT_ACCEPTED {
set utc_time "2025-04-29T14:33:00Z"
set numeric_time [utc_to_numeric_date $utc_time]
log "NumericDate format: $numeric_time"
}
Valid Events
All
virtual
Description This command returns the name of the associated virtual server that
the connection is flowing through.
Example Use the following example to log the name of the virtual server
handling the current HTTP request:
when HTTP_REQUEST {
log "Virtual Server: [virtual name]"
}
Valid Events
All
270
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
when
Description This command allows one to specify an event in an aFleX script. All
aFleX events begin with a when command. Multiple when commands can
be specified within a single aFleX script.
Valid Events
All
whereis
Description This command will return the geo-location information for a given IP
address. The command will search in the geo-location database in use
on the ACOS device. This can be helpful when used in a script that looks
up information in a geo-location database from a third-party vendor.
Example The use of the following example takes a geo-location database from a
third-party vendor to look up the location of clients who send requests
to a specific VIP.
271
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Each entry in this database has 6 fields. The aFleX script uses a GSLB
CSV template to search the data in 4 of the fields:
“ip-from”, “ip-to-mask”, “country”, “”, “”, “continent”
The use of the following example aFleX script performs search in the
database:
when CLIENT_ACCEPTED {
log "This is the country: [IP::client_addr]: [lindex
[whereis [IP::client_addr]] 0]"
log "This is the continent: [IP::client_addr]: [lindex
[whereis [IP::client_addr]] 1]"
}
Example The following steps illustrate the ACOS configuration steps required to
install the geo-location database and use the aFleX script to search the
data in the database.
• The following command will import a geo-location database file in
.csv format onto the ACOS device:
ACOS#import geo-location [Link] use-mgmt-port
scp://root@[Link]:/[Link]
272
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Password []********
Importing ...
Global
273
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• The following command will add the aFleX script to the ACOS
device. The script is copy-pasted into the CLI in this example.
Alternatively, the script can be configured elsewhere and then
imported as a file.
ACOS(config)#aflex create geo-lookup-script
Type in your aFleX script (type . on a line by itself when
done)
when CLIENT_ACCEPTED {
log "Country=[lindex [whereis [Link]] 0]"
log "Continent=[lindex [whereis [Link]] 1]"
• The following commands will bind the aFleX script to a virtual port.
ACOS(config)#slb virtual-server vip-L7-25-130
[Link]
ACOS(config-slb vserver)#port 80 http
ACOS(config-slb vserver-vport)#aflex geo-lookup-script
ACOS(config-slb vserver-vport)#end
274
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
NOTE:
l The provided example does not show real servers and service group
configuration, but they are required. In addition, network
connectivity connection (Network Address Translation (NAT)), may
also be needed.
l The end command is not a part of the VIP configuration. It functions
by returning the CLI prompt to the Privileged EXEC configuration
level.
After some traffic is sent to the VIP, the ACOS log will list the geo-
location information for the client:
ACOS#show log
Log Buffer: 30000
May 15 2012 04:15:37 Info [AFLEX]:geo_test:Continent=ASIA
May 15 2012 04:15:37 Info [AFLEX]:geo_test:Country=CN
May 15 2012 04:15:37 Info [AFLEX]:geo_test:Continent=NORTH
AMERICA
May 15 2012 04:15:37 Info [AFLEX]:geo_test:Country=US
May 15 2012 04:15:37 Info [AFLEX]:geo_test:Continent=NORTH
AMERICA
May 15 2012 04:15:37 Info [AFLEX]:geo_test:Country=US
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• LB_FAILED
• LB_SELECTED
• SERVER_CLOSED
275
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• SERVER_CONNECTED
• SERVER_DATA
276
Global Variable Commands
You can use the following operators to quickly modify global variables across
multiple parameters:
l array
l get
l incre
l set
l unset
277
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
array
Description This command will set or return elements in a global array.
This will set the values of one or more elements in the <global_array>.
array size <global_array>
This will provide a list of names for all the elements in the <global_
array>.
array get <global_array> <key>
Valid Events
All.
get
Description This command will return the value of a global variable.
Valid Events
All
278
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
incre
Description This command will increment the specified global variable by a value of
1. It is different from the Tcl command incr where it alters the global
variables.
Valid Events
All.
set
Description This command will set the value of a local variable.
This will set the <local_variable> to the specified <value>. When the
variable does not exist, a new variable will be created upon this
command’s execution. The recommendation is to use table set/delete
for global variables.
Valid Events
All.
unset
Description This command will unset the value of a local variable.
This will delete the value for the <local_variable>. It also forces the
specified variable to return an empty string.
Valid Events
279
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
All.
280
AAM Commands
The following Application Access Management (AAM) commands are supported:
l AAM::attribute
l AAM::attribute_collection
l AAM::authentication
l AAM::authorization
l AAM::bypass
l AAM::client
l AAM::relay
l AAM::saml
l AAM::session
281
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
AAM::attribute
Description This command will find the attribute value from an attribute collection
in the AAM session according to the attribute name. This command will
return correspondent attribute value to specific attribute name and
multi-valued index.
This returns the value of the attribute specified. Since neither a multi-
valued index or collection ID are specified, the default value of 1 is
assumed for both arguments.
This returns the value of the attribute specified, with the specified
multi-valued index.
AAM::attribute get <attribute-name> collection-id <collection-
id>
This returns the value of the attribute specified within the specified
collection.
AAM::attribute get_multivalue_count <attribute-name>
282
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
NOTE: This command is only supported on HTTP and HTTPS virtual ports.
Valid Events
• AAM_AUTHORIZATION_CHECK
• AAM_RELAY_INIT
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
AAM::attribute_collection
Description This will specify a collection to be used by <collection-id>. If the
backend authentication server type is LDAP, the ACOS device will only
query the attributes defined in this collection.
Valid Events
283
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• AAM_AUTHENTICATION_INIT
AAM::authentication
Description This command will set or return authentication information.
This will set the username for the authentication to the specified value.
AAM::authentication get password
This will set the password for the authentication to the specified value.
AAM::authentication get ntlm_domain
This will set the NTLM domain for the authentication to the specified
value.
For RSA authentication servers, only get username, set username and
get password are supported.
AAM::authentication set server <server_name>
284
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
This will set an authentication service group to the specified name. The
following are the return values:
0: Success
Example Use the following example to append a different prefix to the username
for authentication. The ACOS device will use the username AUTH_$name
for authentication.
when AAM_AUTHENTICATION_INIT {
set name "AUTH_"
append name [AAM::client get username]
AAM::authentication set username $name
log "=$user@$domain="
285
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example For additional examples, see Example 7: Getting a constructed JWT from
a Session.
Valid Events
• AAM_AUTHENTICATION_INIT
• AAM_AUTHORIZATION_CHECK
• AAM_RELAY_INIT
AAM::authorization
Description This command will set or return authorization information.
286
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
This will set the LDAP search filter to the specified [Link] maximum
length of the search filer is 255. Disable 'use Subject DN as LDAP search
base DN' using the disable option. This option is for the client-SSL
template only. The following are the return values:
0: Success
Valid Events
• AAM_AUTHENTICATION_INIT
• AAM_AUTHORIZATION_CHECK
• AAM_RELAY_INIT
AAM::bypass
Description This command will skip the authentication of a specific real server
destination port through EP.
287
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Syntax AAM::bypass
Example Use the following example for specific real server destination port.
when HTTP_REQUEST {
if {[HTTP::host} contains ":1433" } {
AAM::bypass
}
}
Valid Events
• HTTP_REQUEST
AAM::client
Description This command will return information about user input.
This will return the username that was input by the user.
AAM::client get password
This will return the password that was input by the user.
AAM::client get ntlm_domain
This will return the NTLM domain that was input by the user. For
example, if the input for the username were in the format
“domain\username”, this command would return the string “domain”.
AAM::client get authn_realm
This will return the realm used for authentication. For example, if the
input for username were in the format “domain\username” or
“username@domain”, this command would return the string “domain”.
Example Use the following example to append a different prefix to the username
for authentication and relay. The ACOS device will use the username
AUTH_$name for authentication, RELAY_$name for relay, and $name for
authorization.
when AAM_AUTHENTICATION_INIT {
set name [AAM::client get username]
288
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example For additional examples, see Example 7: Getting a constructed JWT from
a Session.
Valid Events
• AAM_AUTHENTICATION_INIT
• AAM_AUTHORIZATION_CHECK
• AAM_RELAY_INIT
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
AAM::relay
Description This will set or return information about relay.
This will set the username used in relay to the specified value.
AAM::relay get password
This will set the password used in relay to the specified value.
AAM::relay get realm
289
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use the following example to append a different prefix to the username
for authentication and relay. The ACOS device will use the username
AUTH_$name for authentication, RELAY_$name for relay, and $name for
authorization.
when AAM_AUTHENTICATION_INIT {
set name [AAM::client get username]
AAM::authentication set username "AUTH_$name"
AAM::relay set username "RELAY_$name"
}
Valid Events
• AAM_AUTHENTICATION_INIT
• AAM_AUTHORIZATION_CHECK
• AAM_RELAY_INIT
AAM::saml
Description SAML is an XML-based markup language for security assertions. This
command returns information about the XML elements.
This command parses the SAML Assertion XML entity and gets XML
element content or attributes from it. The path variable is the XML
element tree path for the SAML Assertion XML entity.
Get content: To get the content of NameID element in the XML entity
use: "AAM::saml get [Link]". The result is "test" in
this case.
290
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
This command parses the SAML Assertion XML entity and gets the
number of contents for an XML element. The path variable is the XML
element tree path for the SAML Assertion XML entity.
Example To get the number of content elements for NameID element in the XML
entity, use "AAM::saml get_multivalue_count
[Link]". The result is 2 in this case.
<saml:Assertion>
<saml:Subject>
<saml:NameID Format="string"> test1 </saml:NameID>
<saml:NameID Format="string"> test2 </saml:NameID>
</saml:Subject>
</saml:Assertion>
Example For more examples with SAML, see Example 7: Getting a constructed
JWT from a Session.
Valid Events
• AAM_AUTHENTICATION_INIT
• AAM_AUTHORIZATION_CHECK
• AAM_RELAY_INIT
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
291
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
AAM::session
Description This will return information about the auth session.
This will return the name of the AAA policy matched for this session.
This command can be used before the authentication session is
established.
AAM::session get matched_aaa_rule
This will return the AAA rule index this session matched. This command
can be used before the authentication session is established.
AAM::session get cookie_domain
This will return the cookie domain of this session. This command must
be used after the authentication session is established. If it is used
before the authentication session is established, it will return an empty
string.
AAM::session get cookie_domain_group
This will return the cookie domain groups of this session. This
command must be used after the authentication session is established.
If it is used before the authentication session is established, it will
return an empty string.
AAM::session set jwt <jwt-message>
This will set the constructed JWT message to the session, so for the
next client request there is no need to re-construct it and it can be
received through the "AAM::session get jwt" command directly.
This will get the constructed JWT from the session if it is set through
the "AAM::session set jwt <jwt-message>" command before.
292
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
• AAM_AUTHENTICATION_INIT
• AAM_AUTHORIZATION_INIT
• AAM_AUTHORIZATION_CHECK
• AAM_RELAY_INIT
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
293
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
when AAM_AUTHENTICATION_INIT {
if { [IP::addr [IP::client_addr] equals [Link]/16] } {
AAM::attribute_collection 1
} else {
AAM::attribute_collection 2
}
}
when AAM_AUTHORIZATION_CHECK {
if { [IP::addr [IP::client_addr] equals [Link]/16] } {
set username_c1 [AAM::attribute get UserName collection_id 1]
294
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
}
}
}
when AAM_AUTHORIZATION_CHECK {
if { [AAM::session get matched_aaa_rule] equals 3 and [AAM::session get
matched_aaa_policy] equals "ldap"} {
set username [AAM::attribute get UserName collection_id 2]
} else {
set username_c2 [AAM::attribute get displayName collection_id 1]
set businessCategory [AAM::attribute get businessCategory collection_i
1]
when HTTP_REQUEST {
295
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
when AAM_AUTHNTICATION_INIT {
if { $reqhost equals “[Link]” } {
AAM::authentication set service-group “SECURE-LDAP-GROUP”
}
# use authenticaion server/service-group in configuration
}
when AAM_AUTHENTICATION_INIT {
if { [IP::addr [IP::client_addr] equals [Link]] } {
AAM::authorization set server “LDAP-INTERNAL”
} else {
AAM::authorization set server “LDAP-EXTERNAL”
}
}
296
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
297
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
298
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
when HTTP_REQUEST_SEND {
set jwt_msg [AAM::session get jwt]
if { $jwt_msg equals "" } {
# check necessary jwt contents
set name [AAM::attribute get Fname collection_id 1]
set role_count [AAM::attribute get_multivalue_count MemberOf]
set nameId [AAM::saml get
[Link]]
set nbf_str [AAM::saml get NotBefore@[Link]]
set exp_str [AAM::saml get NotOnOrAfter@[Link]]
set attr_cnt [AAM::saml get_multivalue_count
[Link]]
# hdr
set jwt_hdr [b64encode "{ \"alg\": \"ES256\", \"typ\": \"JWT\"}"]
log local0.0 "hdr = { \"alg\": \"ES256\", \"typ\": \"JWT\"}"
299
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
# signature
set jwt_signature [b64encode [esha256 "$jwt_hdr.$jwt_payload" ec_
256]]
# jwt
set jwt_msg "$jwt_hdr.$jwt_payload.$jwt_signature"
AAM::session set jwt $jwt_msg
}
300
AES Commands
The following Advanced Encryption Standard (AES) commands are supported:
l AES::decrypt
l AES::encrypt
l AES::key
301
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
AES::decrypt
Description This command will use an AES key to decrypt content.
Example Use the following example to set the key and log a message about
decrypted content.
when HTTP_REQUEST {
set key [AES::key password 256]
log "The AES decrypted content is [AES::decrypt $key
[HTTP::payload]]"
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• LB_FAILED
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
302
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
AES::encrypt
Description This command will use an AES key to encrypt the content.
Example Use the following example to set the key and log a message about
encrypted content.
when SERVER_DATA {
set key [AES::key password 192]
log "The AES encrypted content is [AES::encrypt $key
[TCP::payload]]"
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• LB_FAILED
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
303
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
AES::key
Description This command will use a randomly created key for
encrypting/decrypting data using AES.
The 8-byte header is of the form “AES xxx” where xxx is 128, 192, or 256.
The resulting key file can be 40, 48, or 56 bytes long.
The [256 | 192 | 128] option specifies the key length, in bits. The
default is 128.
Example Use the following example to log a message about the AES key.
when SERVER_DATA {
log "The AES key is [AES::key password]"
}
Valid Events
All.
304
Application Firewall Commands
The following commands related to application firewall are supported:
l APPCLS::application
305
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
APPCLS::application
Description Use the command to view information about the application protocol
and category name from the connection. The command is only
supported when you have configured application firewall for your ACOS
system and you have a valid QOSMOS license. The command only
supports TCP and UDP data plane events and TCP and UDP type
services. At least one single application firewall rule must be configured
to enable application classification. Application classification needs
several packet exchanges, so you cannot predict at which aFleX event
the classification is completed. Application Level Gateway (ALG) is not
supported.
Example The following script returns a list of application protocol names. The
value returned can be pending for a pending state, a blank string for no
application protocol names, or the name of the application protocol if
one is configured.
when HTTP_REQUEST {
log "app protocol = '[APPCLS::application get protocol]'"
}
Example The following script returns a classification path. The value returned
can be a blank string for no application classification path, or the name
of the application classification path if one is configured.
306
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
when HTTP_REQUEST {
log "app path = '[APPCLS::application get classification-
path]'"
}
Example The following script returns the list of application category names. The
value returned can be pending for a pending state, a blank string for no
category names, or the names of the categories of the most classified
protocols.
when HTTP_REQUEST {
log "app category = '[APPCLS::application get category]'"
}
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_CLIENTHELLO
• CLIENTSSL_DATA
• CLIENTSSL_HANDSHAKE
• SERVERSSL_CLIENTHELLO_SEND
• SERVERSSL_DATA
• SERVERSSL_HANDSHAKE
• SERVERSSL_SERVERHELLO
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
307
Category Commands
The following category commands is supported:
l CATEGORY::lookup
308
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
CATEGORY::lookup
Description It accepts one parameter (URL) input. This returns the web category
received from local library or Bright Cloud server.
Syntax CATEGORY::lookup
309
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
when DNS_REQUEST {
log "Received DNS request for: [DNS::question name]"
set query_name [DNS::question name]
Valid Events
310
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
311
Class List Commands
The following class list commands are supported, but currently limited to non-Aho-
Corasick access lists:
l CLASS::exists
l CLASS::match
l CLASS::names
l CLASS::type
NOTE: The class-list must be configured and attached to the same vport as
the aFleX script using a policy template.
NOTE: Class list commands require the LID to be defined in the configuration,
either globally or on the virtual-server or virtual port.
NOTE: Multiple LID definitions may be available for a non-global LID. This
includes a LID in a policy template bound to a virtual port, a LID in a
DNS template bound to a virtual port, a LID in a policy template bound
to a virtual server, and a LID configured in a system-wide policy
template. For more information, see Limit ID Commands.
312
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
CLASS::exists
Description This example will return a Boolean value that indicates whether the
class list exists.
Example Use the following example to log when a class list exists.
when HTTP_REQUEST {
log "The class exists for [CLASS::exists example_list]."
}
Valid Events
• CACHE_REQUEST
• CACHE_RESPONSE
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
• DNS_REQUEST
• DNS_RESPONSE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• LB_FAILED
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
313
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• SIP_REQUEST
• SIP_REQUEST_SEND
• SIP_RESPONSE
CLASS::match
Description Queries class lists to check for matches and returns any component of a
matching entry.
NOTE: Queries to a string class list are case sensitive. Queries to a DNS class
are not case sensitive.
NOTE: In this release, string class lists can be referenced by name and
externally modified.
NOTE: Class commands read class lists only and do not modify the entries in
any way.
This will return whether <param> matches an [ip | dns] entry in class
list <list-name>. Omitting the [ip | dns] argument will result in IP
entries in the class list being searched first, followed by DNS entries.
CLASS::match <param> <list-name> <key> [ip | dns]
This will return the key of the match when <param> matches an [ip |
dns] entry in class list <list-name>. Omitting the [ip | dns] argument
will result in IP entries in the class list being searched first, followed by
DNS entries.
CLASS::match <param> <list-name> <lid> [ip | dns]
This will return the LID of the match (only if configured) when <param>
matches an [ip | dns] entry in classlist <list-name>. Omitting the [ip
| dns] argument will result in IP entries in the class list being searched
first, followed by DNS entries.
314
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
or
[CLASS::match [IP::client_addr] $classlist ip]
This will return the key of the match when <param> matches an entry in
class list <list-name>.
CLASS::match <param> <operator> <list-name> <lid>
This will return the LID of the match when <param> matches an entry in
class list <list-name>.
CLASS::match <param> <operator> <list-name> <value>
315
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
This will return the value of the match when <param> matches an entry
in class list <list-name>.
NOTE: The maximum number of string entries for a class list depends on the
total available system memory of the ACOS device.
Example
when HTTP_REQUEST {
log "The class match is [CLASS::match [Link] ends_
with example_hosts]"
log "The class match key is [CLASS::match www starts_with
example_hosts key]"
log "The class match lid is [CLASS::match [Link]
equals example_hosts lid]"
log "CLASS Match value: [CLASS::match [Link]
equals example_hosts value]"
}
Example Use the following example to redirect an HTTP request to the URL that
has an entry in the class list.
when HTTP_REQUEST {
set uri [string tolower [HTTP::uri]]
set redirect_url [CLASS::match $uri equals value]
if { not ($redirect_url equals "") } {
HTTP::redirect $redirect_url
log "The redirected $uri is $redirect_url" }
}
}
316
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
• CACHE_REQUEST
• CACHE_RESPONSE
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
• DNS_REQUEST
• DNS_RESPONSE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• LB_FAILED
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
• SIP_REQUEST
• SIP_REQUEST_SEND
• SIP_RESPONSE
CLASS::names
Description This command will return a list of class-list names.
Syntax CLASS::names
317
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
when HTTP_REQUEST {
log "CLASS Name: [CLASS::names]"
}
Valid Events
• CACHE_REQUEST
• CACHE_RESPONSE
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
• DNS_REQUEST
• DNS_RESPONSE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• LB_FAILED
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
• SIP_REQUEST
• SIP_REQUEST_SEND
• SIP_RESPONSE
CLASS::type
Description This command will return the type of the specified class list.
318
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
The type value that can be returned by aFleX depends on whether the
type was explicitly specified during class-list configuration. If the type is
a pair of empty brackets ( [] ), the class list does not contain any
entries.
• Explicitly configured: dns, ipv4, ipv6, string
• Implicitly configured by the ACOS device based on the class-list
entries: [], [dns], [ipv4], [ipv6], [dns, ipv4], [dns, ipv6]
Example Use the following example to log the class type for the class-list name.
when HTTP_REQUEST {
log "The class type for example_ips is [CLASS::type
example_ips]"
log "The class type for example_hosts is [CLASS::type
example_hosts]"
}
Valid Events
• CACHE_REQUEST
• CACHE_RESPONSE
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
• DNS_REQUEST
• DNS_RESPONSE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• LB_FAILED
319
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
• SIP_REQUEST
• SIP_REQUEST_SEND
• SIP_RESPONSE
320
Compression Commands
The following compression commands are supported on HTTP traffic (original proxy)
and HTTP2 traffic (new proxy):
l COMPRESS::brotli
l COMPRESS::disable
l COMPRESS::enable
l COMPRESS::gzip
COMPRESS::brotli
Description Brotli (RFC 7932) is a lossless compression technique that compresses
data utilizing a combination of the LZ77 algorithm. ADC supports Brotli
compression and decompression for HTTP/2 protocol and HTTP/1
traffic is also supported when compression algorithm is specified
through method order command under http template or via aFleX.
Specify the value of the window size (i.e. value of lgwin) of Brotli.
Example Use the following example to set the brotli compression level.
when HTTP_REQUEST {
COMPRESS::enable
COMPRESS::brotli level 4
}
321
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
COMPRESS::enable
COMPRESS::brotli level 4
COMPRESS::brotli sliding-window 5
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
322
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
COMPRESS::disable
Description This command will disable the compression for an HTTP response.
Syntax COMPRESS::disable
Example Use the following example to check if a particular header response does
not exist, and then disable compression.
when HTTP_RESPONSE {
if { not ([HTTP::header exists "Accept-Encoding"]) } {
COMPRESS::disable
}
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
COMPRESS::enable
Description This command will enable compression for an HTTP response.
323
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Syntax COMPRESS::enable
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
COMPRESS::gzip
Description This command will set the level for HTTP compression.
324
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
NOTE: Setting the compression level to a higher value results in more HTTP
compression at a greater CPU cost. Additional CPU usage can outweigh
the benefit of a higher level. For example, setting compression to level 6
can provide equivalent performance to level 9. For best performance,
A10 Networks recommends setting compression to level 1.
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
325
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
COMPRESS::method_order
Description Sets the order of the compression algorithm to use when multiple
algorithms are available. This allows control over whether Brotli, GZIP,
or other supported methods are prioritized when compressing
responses. This command must be used after enabling compression via
COMPRESS::enable.
This command allows you to specify the priority of Brotli, GZIP, or other
supported compression algorithms when compressing responses. It
should be used only after enabling compression with
COMPRESS::enable.
Example Use the following example to define the preferred order of compression
algorithm:
when HTTP_REQUEST {
COMPRESS::enable
COMPRESS::brotli level 4
COMPRESS::brotli sliding-window 5
COMPRESS::method_order gzip brotli
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• SERVER_CLOSED
• SERVER_CONNECTED
326
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• SERVER_DATA
327
Database Load-Balancing Commands
The following commands related to database load balancing (DBLB) are supported:
l DB::command
l DB::query
328
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
DB::command
Description The command returns a numeric value that represents the command
number.
Syntax DB::command
Example Use the following example to log the DB command value to the
assigned service group.
when DB_COMMAND {
log "DB Command: [DB::command]"
pool mssg1_service_group
}
Valid Events
DB_COMMAND
DB::query
Description This command returns a string that holds the entire SQL query which
was sent by the client.
Syntax DB::query
Example Use the following example to log the DB query value to the assigned
service group.
when DB_QUERY {
log "DB Query: [DB::query]"
pool mssg1_service_group
}
Valid Events
DB_QUERY
329
Diameter Load-Balancing Commands
You can use the following operators to quickly modify global variables across
multiple parameters:
l DIAMETER::app_id
l DIAMETER::avp
l DIAMETER::cmd_code
l DIAMETER::length
l DIAMETER::version
330
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
DIAMETER::app_id
Description This command returns the application ID of a Diameter message.
Syntax DIAMETER::app_id
Example Use the following example to log the Diameter App ID value.
when DIAMETER_REQUEST {
log "The DIAMETER::app_id is [DIAMETER::app_id]"
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• DIAMETER_ANSWER
• DIAMETER_ANSWER_SEND
• DIAMETER_REQUEST
• DIAMETER_REQUEST_SEND
• SERVER_CLOSED
DIAMETER::avp
Description This command is used to read, write, or delete AVPs.
This command returns a list of the IDs of AVPs with matching <avp_
code> or <name>. If the <avp_code> or <name> is not specified, the IDs of
all AVPs are returned.
331
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
NOTE: The order of IDs might not be the same as the order of the AVPs in the
packet.
This command returns the numeric AVP code of the AVP with ID <id>. If
the [name] is specified and the AVP is a standard AVP, a user-readable
string is returned; otherwise, an empty string is returned. If [type] is
specified, and the AVP is a standard AVP, its type is returned;
otherwise, an empty string is returned.
DIAMETER::avp <id> index
This command returns the index value within the packet of the AVP
with ID <id>.
DIAMETER::avp <id> flags
This command returns flags of the AVP with ID <id> in the following
format: {V|-}{M|-}{P|-}
DIAMETER::avp <id> length
This command returns the vendor_id of the AVP with ID <id> if the AVP
has the “V” flag specified; otherwise, an empty string is returned.
DIAMETER::avp <id> value [<type>]
This command returns the value of the AVP with ID <id>. If the specified
<type> is Unsigned32, Unsigned64, Integer32, Integer64, Address, or
OctetString, the value is interpreted accordingly if it does not conflict
with the AVP (for example, for an Integer32 AVP, Unsigned64 cannot be
returned). For AVPs of type DiameterIdentity, Grouped, Time, DiamURI,
Enumerated, or UTF8String, a byte array is returned.
DIAMETER::avp <id> delete
332
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use the following example to log the AVP count, ID values, ID values for
code 257, and session IDs.
when DIAMETER_REQUEST {
log "Number of AVPs = [DIAMETER::avp count]"
log "Ids of all AVPs = [DIAMETER::avp get_ids]"
log "Ids of AVPs of code 257 = [DIAMETER::avp get_ids 257]"
log "Ids of Session-Id AVPs = [DIAMETER::avp get_ids
Session-Id]"
}
Example Use the following example to incrementally log ID codes, code names,
code types, index values, flag values, and message lengths.
when DIAMETER_REQUEST {
set ids [DIAMETER::avp get_ids]
for { set i 0 } { $i < [llength $ids] } { incr i } {
set id [lindex $ids $i]
log "DIAMETER::avp $id code = [DIAMETER::avp $id code]"
log "DIAMETER::avp $id code name = [DIAMETER::avp $id code
name]"
log "DIAMETER::avp $id code type = [DIAMETER::avp $id code
type]"
333
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use the following example to insert a new AVP to the Diameter message
and then log AVP code, code names, code types, index values, flag
values, message length, and vendor IDs of the new AVP.
when DIAMETER_REQUEST_SEND {
set newid [DIAMETER::avp insert 12345 6789 VMP 567 type
Unsigned32]
log "DIAMETER::avp $newid code = [DIAMETER::avp $newid code]"
log "DIAMETER::avp $newid code name = [DIAMETER::avp $newid
code name]"
log "DIAMETER::avp $newid code type = [DIAMETER::avp $newid
code type]"
log "DIAMETER::avp $newid index = [DIAMETER::avp $newid
index]"
log "DIAMETER::avp $newid flags = [DIAMETER::avp $newid
flags]"
log "DIAMETER::avp $newid length = [DIAMETER::avp $newid
length]"
log "DIAMETER::avp $newid vendor_id = [DIAMETER::avp $newid
vendor_id]"
log "DIAMETER::avp $newid value Unsigned32 = [DIAMETER::avp
$newid value Unsigned32]"
334
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use the following example to add a new AVP with ID 12345 and then
replace the values for Flag and Type. Log AVP index, flags, message
length, and vendor ID.
when DIAMETER_REQUEST_SEND {
set newid [DIAMETER::avp 0 insert 12345 6789 VMP 567 type
Unsigned32]
DIAMETER::avp $newid replace value 12345 type Unsigned32 flags
VMP 567
log "DIAMETER::avp $newid index = [DIAMETER::avp $newid
index]"
log "DIAMETER::avp $newid flags = [DIAMETER::avp $newid
flags]"
log "DIAMETER::avp $newid length = [DIAMETER::avp $newid
length]"
log "DIAMETER::avp $newid vendor_id = [DIAMETER::avp $newid
vendor_id]"
log "DIAMETER::avp $newid value Unsigned32 = [DIAMETER::avp
$newid value Unsigned32]"
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• DIAMETER_ANSWER
• DIAMETER_ANSWER_SEND
• DIAMETER_REQUEST
• DIAMETER_REQUEST_SEND
• SERVER_CLOSED
DIAMETER::cmd_code
Description This command returns the command code, or its name of a Diameter
message. If [name] is specified, an empty string or one of the following
335
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
is returned as appropriate: ASR, ASA, ACR, ACA, CER, CEA, DWR, DWA,
DPR, DPA, RAR, RAA, STR, or STA.
If you use the [name] option, the name is returned,. If you omit the
[name] option, the command code is returned instead.
Example Use the following example to log the Diameter code value.
when DIAMETER_REQUEST {
log "DIAMETER::cmd_code = [DIAMETER::cmd_code]"
}
Example Use the following example to log the Diameter code name.
when DIAMETER_REQUEST {
log "DIAMETER::cmd_code name = [DIAMETER::cmd_code name]"
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• DIAMETER_ANSWER
• DIAMETER_ANSWER_SEND
• DIAMETER_REQUEST
• DIAMETER_REQUEST_SEND
• SERVER_CLOSED
DIAMETER::length
Description This command returns the length of a Diameter message.
Syntax DIAMETER::length
Example Use the following example to log the Diameter message length.
when DIAMETER_REQUEST {
log "DIAMETER::length = [DIAMETER::length]"
336
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• DIAMETER_ANSWER
• DIAMETER_ANSWER_SEND
• DIAMETER_REQUEST
• DIAMETER_REQUEST_SEND
• SERVER_CLOSED
DIAMETER::version
Description This command returns the version of a Diameter message.
Syntax DIAMETER::version
Example Use the following example to log the Diameter version value.
when DIAMETER_REQUEST {
log "DIAMETER::version = [DIAMETER::version]"
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• DIAMETER_ANSWER
• DIAMETER_ANSWER_SEND
• DIAMETER_REQUEST
• DIAMETER_REQUEST_SEND
• SERVER_CLOSED
337
DNS Commands
The following DNS commands are supported:
l DNS::additional
l DNS::answer
l DNS::authority
l DNS::cache
l DNS::class
l DNS::header
l DNS::is_dnssec
l DNS::len
l DNS::name
l DNS::opt
l DNS::query
l DNS::question
l DNS::rdata
l DNS::return
l DNS::rr
l DNS::ttl
l DNS::type
338
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
DNS::additional
Description This command returns, inserts, removes, or clears RRs from the
Additional section. With no arguments, the command returns a Tcl list
of RR objects. With an argument, the command inserts/removes RR Tcl
objects in the Additional section or clears all RRs from the Additional
section.
Example Use the following example to insert RR Tcl objects in the Additional
section.
when DNS_RESPONSE {
set rr [DNS::rr "[Link]. 3600 IN A [Link]"]
DNS::additional insert $rr
}
Valid Events
• DNS_REQUEST
• DNS_RESPONSE
DNS::answer
Description This command returns, inserts, removes, or clears RRs from the Answer
section. With no arguments, this command returns a Tcl list of RR
objects. With an argument, this command inserts or removes RR Tcl
objects in the Answer section or clears all RRs from the Answer section.
Example Use the following example to set RR objects for a DNS response.
when DNS_RESPONSE {
set rr [DNS::rr [Link] 149 IN A [Link]]
DNS::answer insert $rr
log "rrs = '[DNS::answer]'"
}
339
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use the following example to remove SOA records from the Answer
section.
when DNS_RESPONSE {
set rr [DNS::rr [Link] 149 IN A [Link]]
DNS::answer insert $rr
log "DNS Answer: [DNS::answer]"
}
Example Use the following example to remove one RR from the answer.
when DNS_RESPONSE {
set rrs [DNS::answer]
set i 0
foreach rr $rrs {
log "i = $i rr = '$rr'"
incr i
}
set rr1 [lindex $rrs 0]
log "remove rr1 = '$rr1'"
DNS::answer remove $rr1
set k 0
foreach rr [DNS::answer] {
log "k = $k rr = '$rr'"
incr k
}
}
Valid Events
• DNS_REQUEST
• DNS_RESPONSE
DNS::authority
Description This command returns, inserts, removes, or clears RRs from the
Authority section. With no arguments, this command returns a Tcl list
of RR objects. With an argument, this command returns inserts or
removes RR Tcl objects in the Authority section or clears all RRs from
the Authority section.
340
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use the following example to remove all the authority records.
when DNS_RESPONSE {
set rrs [DNS::answer]
set i 0
foreach rr $rrs {
log " i = $i rr ='$rr'"
incr i
}
set rrs2 [DNS::authority]
set j 0
foreach rr2 $rrs2 {
log "j = $j rr2 = '$rr2'"
incr j
}
DNS::authority clear
}
Example Use the following example to remove a single authority record if there
is more than one authority record.
when DNS_RESPONSE {
set rrs2 [DNS::authority]
set rr2 [lindex $rrs2 1]
DNS::authority remove $rr2
}
Valid Events
• DNS_REQUEST
• DNS_RESPONSE
DNS::cache
Description This command controls the DNS cache access and update for the
current DNS session.
341
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
NOTE: This command enables or disables the DNS cache for the current DNS
session.
NOTE: This command is only effective when global DNS cache or a DNS cache
template is enabled.
DNS::cache update
NOTE: This command updates the DNS cache with content changed through
aFleX.
Example Use the following example to bypass the cached response for a DNSSEC
query.
when DNS_REQUEST {
if {[DNS::is_dnssec]} {
log "This is DNSSEC request!"
DNS::cache disable
}
}
Valid Events
• DNS_REQUEST
• DNS_RESPONSE
DNS::class
Description This command gets or sets the resource record class field (IN, CH, HS,
and so on).
Example Use the following example to insert a record for a DNS response.
when DNS_RESPONSE {
set rr [DNS::rr [Link] 149 IN A [Link]]
set rr1 [DNS::class $rr HS]
DNS::answer insert $rr1
}
342
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
• DNS_REQUEST
• DNS_RESPONSE
DNS::header
Description This command gets or sets simple bits or byte fields. Return value is
always an integer except for successful recognition of the rcode or
opcode fields, where a string is returned.
343
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use the following example to log all questions and responses for DNS
requests and responses:
when DNS_REQUEST {
log "Client: [IP::client_addr] Question:[DNS::question name]
Type:[DNS::question type] Class:[DNS::question class]"
set fqdn [DNS::question name]
}
when DNS_RESPONSE {
log "Request: $fqdn Answer: [DNS::answer] Status:
[DNS::header rcode] Flags: RD [DNS::header rd] RA [DNS::header
ra]"
}
Valid Events
• DNS_REQUEST
• DNS_RESPONSE
DNS::is_dnssec
Description This command checks for a DNSSEC query or reply. It returns 1 if true
and 0 if false.
Syntax DNS::is_dnssec
344
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
if {[DNS::is_dnssec]} {
log "This is DNSSEC request!"
}
}
Valid Events
• DNS_REQUEST
• DNS_RESPONSE
DNS::len
Description This command returns the DNS packet message length.
Syntax DNS::len
Example Use the following example to log the packet length for a DNS request.
when DNS_REQUEST {
log "DNS len: [DNS::len]"
}
Example Use the following example to log the packet length for a DNS response.
when DNS_RESPONSE {
log "DNS len: [DNS::len]"
}
Valid Events
• DNS_REQUEST
• DNS_RESPONSE
DNS::name
Description This command gets or sets the resource record name field (FQDN); for
example, “[Link]”.
Example Use the following example to set the FQDN for a DNS response.
345
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
when DNS_RESPONSE {
set rr [DNS::rr [Link] 149 IN A [Link]]
set rr1 [DNS::name $rr "[Link]"]
DNS::answer insert $rr1
}
Valid Events
• DNS_REQUEST
• DNS_RESPONSE
DNS::opt
Description This command gets or sets the parameters of a DNS OPT record. If there
is no OPT record in the DNS content, the return value is NULL for ‘get’
commands.
NOTE: This command gets or sets the DO value for DNSSEC in an OPT record.
NOTE: This command gets or sets the UDP size value in an OPT record.
NOTE: This command gets or sets the extended RCODE value in an OPT record.
Example Use the following example to log DNS opt record for DNS requests and
responses.
when DNS_REQUEST {
if { [DNS::is_dnssec] } {
log "This is DNSSEC request!"
log "DNS opt udpsize: [DNS::opt udpsize]"
346
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
}
}
when DNS_RESPONSE {
if { [DNS::opt do] } {
DNS::opt udpsize 8196
}
}
Valid Events
• DNS_REQUEST
• DNS_RESPONSE
DNS::query
Description This command returns a Tcl list of RR Tcl objects lists, one for each
section: Answer, Authority, and Additional.
NOTE: The <target> can be “dnsx”. The <name> is the fully qualified domain
name (for example, “[Link]”). The <type> specifies the
record type (A, AAA, MX, NPTR, and so on). The dnssec option gets
DNSSEC data.
Example Use the following example to return RR Tcl objects for a DNS response.
when DNS_RESPONSE {
set rrtcl [DNS::query dnsx [Link] SOA]
foreach rrs $rrtcl {
foreach rr $rrs {
if { [DNS::type $rr] equals "SOA" } {
DNS::additional insert $rr
}
}
}
}
Valid Events
• DNS_REQUEST
347
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• DNS_RESPONSE
DNS::question
Description This command gets or sets the question field value. A question RR has
no rdata and only requests with qdcount == 1 are accepted. The return
types for name, type, and class are all strings. Type returns/accepts any
of the valid DNS types defined in the RFCs. The class returns/accepts IN,
CH, and HS.
Example Use the following example to set a question field name and object for a
DNS request and response.
when DNS_REQUEST {
if { [DNS::question name] contains "[Link]"
} {
log "DNS Question name: [DNS::question name]"
DNS::question name "[Link]"
}
}
when DNS_RESPONSE {
set rr_ext [DNS::rr [Link] 300 IN A
[Link]]
set rr_int [DNS::rr [Link] 300 IN A
[Link]]
if { [DNS::question name] contains "[Link]"
} {
log "Original response question name: [DNS::question
name]"
DNS::answer insert $rr_int
} elseif { [DNS::question name] contains
"[Link]" } {
DNS::answer insert $rr_ext
}
}
Valid Events
• DNS_REQUEST
348
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• DNS_RESPONSE
DNS::rdata
Description This command gets or sets the resource record rdata field.
Example Use the following example to set a resource record object for a DNS
request.
when DNS_RESPONSE {
set rr [DNS::rr [Link] 149 IN A [Link]]
set rr2 [DNS::rdata $rr "[Link]"]
DNS::answer insert $rr2
}
Valid Events
• DNS_REQUEST
• DNS_RESPONSE
DNS::return
Description This command skips all further processing after Tcl execution and sends
the DNS packet in the opposite direction.
Syntax DNS::return
NOTE: When responding to a DNS query in the event DNS_REQUEST, you must
use DNS::return in order to prevent the response being overwritten by
the real DNS server or by the GSLB function when running GSLB on
ACOS."
Example Use the following example to set a resource record name and object for
a DNS request.
when DNS_REQUEST {
if { [DNS::question name] contains "[Link]" } {
DNS::header qr 1
349
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
DNS::header ra 1
set name [DNS::question name]
set rr1 [DNS::rr $name 0 IN CNAME
[Link]]
DNS::answer insert $rr1
DNS::return
}
}
Valid Events
• DNS_REQUEST
• DNS_RESPONSE
DNS::rr
Description This command creates a new resource record object with the specified
attributes.
NOTE: The <name> is the FQDN (for example, “[Link]”). The <ttl>
specifies time to live in seconds. The <class> specifies the DNS class
(IN, CH, HS, and so on). The <type> specifies the record type (A, AAA,
MX, NPTR, and so on). The <rdata> value depends on the type of RR.
For example for an A record, the <rdata> will be an IP address
(“X.X.X.X”).
Example Use the following example to set a resource record object for a DNS
response.
when DNS_RESPONSE {
set rr [DNS::rr [Link] 149 IN A [Link]]
log "DNS rr: $rr"
}
Example Use the following example to set a resource record name and object for
a DNS response.
when DNS_RESPONSE {
set name [DNS::question name]
350
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
• DNS_REQUEST
• DNS_RESPONSE
DNS::ttl
Description This command gets or sets the resource record TTL field.
Example Use the following example to set resource record TTL field for a DNS
response.
when DNS_RESPONSE {
set rr [DNS::rr [Link] 149 IN A [Link]]
set rr1 [DNS::ttl $rr 200]
DNS::answer insert $rr1
}
Valid Events
• DNS_REQUEST
• DNS_RESPONSE
DNS::type
Description This command gets or sets the resource record type field (A, AAAA, MX,
NPTR, etc.).
Example Use the following example to set the resource record for a DNS
response.
when DNS_RESPONSE {
set rr [DNS::rr [Link] 149 IN A [Link]]
set rr1 [DNS::type $rr CNAME]
351
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
• DNS_REQUEST
• DNS_RESPONSE
352
Financial Information eXchange Commands
The following commands related to Financial Information eXchange (FIX) are
supported:
l FIX::begin_string
l FIX::body_length
l FIX::msg_seq_num
l FIX::msg_type
l FIX::sender_compid
l FIX::sending_time
l FIX::target_compid
353
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
FIX::begin_string
Description This command returns the value of the BeginString tag. The BeginString
tag identifies the beginning of a new FIX message and the FIX protocol
version. It is always the first field in the message and is always
unencrypted.
Syntax FIX::begin_string
NOTE: This event is only valid on TCP-proxy and FIX virtual ports.
Example Use the following example to log the beginning string for a FIX request.
when FIX_REQUEST {
log "FIX begin_string: [FIX::begin_string]"
}
Valid Events
• FIX_REQUEST
• FIX_RESPONSE
FIX::body_length
Description This command returns the value of the BodyLength tag. The FIX
BodyLength tag gives the message length in bytes, forward to the
CheckSum field. It is always the second field in the FIX message and is
always unencrypted.
Syntax FIX::body_length
NOTE: This event is only valid on TCP-proxy and FIX virtual ports.
Example Use the following example to log the body length of a FIX request.
when FIX_REQUEST {
log "FIX body_length: [FIX::body_length] bytes"
}
354
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
• FIX_REQUEST
• FIX_RESPONSE
FIX::msg_seq_num
Description This command returns the integer message sequence number. It is
always a positive value.
Syntax FIX::msg_seq_num
NOTE: This event is only valid on TCP-proxy and FIX virtual ports.
Example Use the following example to log the message sequence number of a FIX
request.
when FIX_REQUEST {
log "FIX msg_seq_num: [FIX::msg_seq_num]"
}
Valid Events
• FIX_REQUEST
• FIX_RESPONSE
FIX::msg_type
Description This command returns the value of the MsgType tag. The MsgType tag
defines the message type, which is a string that is one or two
characters in length. It is always the third field in the message and is
always unencrypted.
Syntax FIX::msg_type
NOTE: A “U” as the first character in the MsgType field (examples: U, U2, and
so on) indicates that the message format is privately defined between
the sender and receiver.
355
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
NOTE: This event is only valid on TCP-proxy and FIX virtual ports.
Example Use the following example to log the message type of a FIX request.
when FIX_REQUEST {
log "FIX msg_type: [FIX::msg_type]"
}
Valid Events
• FIX_REQUEST
• FIX_RESPONSE
FIX::sender_compid
Description This command returns the value of the SenderCompID tag. The
SenderCompID is an assigned string value used to identify the firm
sending the FIX message.
Syntax FIX::sender_compid
NOTE: This event is only valid on TCP-proxy and FIX virtual ports.
Example Use the following example to log the sender company ID of a FIX
request.
when FIX_REQUEST {
log "FIX sender_compid: [FIX::sender_compid]"
}
Valid Events
• FIX_REQUEST
• FIX_RESPONSE
FIX::sending_time
Description This command returns the value of the time of message transmission,
always expressed in UTC time. The time is returned as a string in either
of the following formats:
356
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Syntax FIX::sending_time
NOTE: This event is only valid on TCP-proxy and FIX virtual ports.
Example Use the following example to log the timestamp of a FIX request.
when FIX_REQUEST {
log "FIX sending_time: [FIX::sending_time]"
}
Valid Events
• FIX_REQUEST
• FIX_RESPONSE
FIX::target_compid
Description This command returns the value of the TargetCompID tag. The
TargetCompID is an assigned string value used to identify the firm
receiving the FIX message.
Syntax FIX::target_compid
NOTE: This event is only valid on TCP-proxy and FIX virtual ports.
Example Use the following example to log the target company ID of a FIX
request:
when FIX_REQUEST {
log "FIX target_compid: [FIX::target_compid]"
}
357
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
• FIX_REQUEST
• FIX_RESPONSE
358
HTTP Commands
The following HTTP commands are supported on HTTP traffic (original proxy) and
HTTP2 traffic (new proxy):
l HTTP::close
l HTTP::collect
l HTTP::cookie
l HTTP::disable
l HTTP::fallback
l HTTP::header
l HTTP::host
l HTTP::is_keepalive
l HTTP::is_redirect
l HTTP::method
l HTTP::path
l HTTP::password
l HTTP::payload
l HTTP::query
l HTTP::redirect
l HTTP::release
l HTTP::request
l HTTP::retry
l HTTP::request_num
l HTTP::respond
l HTTP::status
l HTTP::stream
l HTTP::uri
359
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
l HTTP::username
l HTTP::version
360
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
HTTP::close
Description This command will insert a “Connection: close” header and close the
HTTP connection.
Syntax HTTP::close
Example Use the following examples to close the HTTP connection after sending
a response.
when HTTP_REQUEST {
if { not ([IP::addr [IP::client_addr] equals
[Link]/24]) } {
HTTP::close
}
}
when ICAP_RESPONSE {
if { not ([IP::addr [IP::client_addr] equals [Link]/24])
} {
HTTP::close
}
}
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
• ICAP_RESPONSE
HTTP::collect
Description This command will collect the amount of data specified using the
<length> argument. When the system collects the specified amount of
361
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
NOTE: This command supports old SSL (N5) and new SSL (QAT, new N5, and
Software TLS1.3).
Syntax HTTP::collect
This will collect data. It is important to note when the content length is
dropped, as it may strand your connection.
HTTP::collect [<length>]
This will collect the amount of data that is specified with the <length>
argument. Specifying a value larger than the actual length may strand
your connection.
• When the <length> option is not applied, the ACOS device behaves
as follows:
• When the packet has an HTTP Content-Length header, the ACOS
device will collect as much data as specified by the header, up to
1.25 MB, the maximum allowable limit.
• When the packet does not have an HTTP Content-Length header,
the ACOS device keeps collecting data until one of the following
occurs:
• The collection of 1.25 MB of data (This is the maximum limit.)
• A zero-size chunk-encoded packet is obtained
• RST is obtained from the server
• FIN is obtained from the server
• Typically, a packet without a Content-Length header is a chunk-
encoded packet.
362
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
NOTE:
• The ACOS device will buffer the entire payload before responding
to the client, so when the object to be collected is huge, there may
be a performance hit.
• If RAM caching is enabled, the HTTP::collect command is not
supported.
• When the HTTP::payload replace command is used in the same
aFleX policy as the HTTP::collect command:
• For packets not containing chunk-encoded data, the ACOS device
replaces the collected data with the specified string.
• For chunk-encoded packets, the command de-chunks the packet
first, removing the chunk header and assembling the packet. The
ACOS device will then replace the content with the new string
without re-chunking the payload. The packet received by the client
will not be chunk-encoded.
• The HTTP::payload replace command supports only clear text
replacement. If the server response is compressed (transfer-
encoded, tar, gz, bz, and so on), it will not work correctly.
Therefore, when HTTP::collect is used in an aFlex policy (also
with event HTTP_RESPONSE), the “Accept-Encoding” header will be
automatically removed from the Request.
Example Use the following example to collect the amount of data specified using
the length argument.
when HTTP_RESPONSE {
if { ([HTTP::status] == 200) and ([HTTP::header "Content-
Type"] contains "text") } {
if { [HTTP::header exists Content-Length] } {
HTTP::collect [HTTP::header Content-Length]
} else {
HTTP::collect
}
}
Valid Events
• HTTP_REQUEST
363
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
HTTP::cookie
Description This command is used to query or manipulate cookies in HTTP requests
and responses. It replaces the http_cookie command.
By default, ACOS operates according to RFC 2109 and RFC 2965. When
an extension attribute or an unknown attribute is encountered, ACOS
stops parsing the remaining response cookie header and forwards the
response to client as received from the server.
This will return the names of all the cookies present in the HTTP header.
HTTP::cookie count
This will return the number of cookies present in the HTTP header.
HTTP::cookie [value] <name> [string]
1 The "SameSite" attribute is not in the predefined list of RFC 2109 and RFC 2965
and is available only in the draft-updates of RFC 6265.
364
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
This will set or get the cookie value of the given name in an HTTP
request. Drop the keyword value from this command if the cookie
name does not collide with any of the other commands.
HTTP::cookie encrypt <name> <pass phrase> ["128" | "192" |
"256"]
Encrypts the value for the given cookie using a key generated from the
pass phrase.
HTTP::cookie decrypt <name> <pass phrase> ["128" | "192" |
"256"]
Decrypts the value for the given cookie using a key generated from the
pass phrase.
HTTP::cookie version <name> [version]
This will set or get the cookie port lists for V2 cookies.
HTTP::cookie insert name <name> value <value> [path <path>]
[domain <domain>] [version <0 | 1 | 2>]
This will add or replace a cookie in an HTTP response. The default value
for the version is 0.
HTTP::cookie remove <name>
This will remove everything except the specified attributes from the
cookie.
HTTP::cookie exists <name>
365
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
This will set or get the max-age. Version 1 cookies and response
messages are only affected by this.
HTTP::cookie expires <name> [seconds] [absolute | relative]
This will set or get the expires attribute. Version 0 cookies are only
affected. If an absolute argument is specified, the seconds value will
represent the number of seconds based from the UNIX epoch, which is
January 1, 1970. The default number of seconds is relative, which is the
number of seconds from the current time. It applies to response
messages only.
HTTP::cookie comment <name> [comment]
This will set or get the cookie comment. Version 1 cookies and response
messages are only affected by this.
HTTP::cookie secure <name> [enable | disable]
This will set or get the value of the secure attribute. Response
messages are only affected by this.
HTTP::cookie commenturl <name> [commenturl]
This will set or get the comment URL. Version 2 cookies and response
messages are only affected by this.
HTTP::cookie discard <name> [enable | disable]
This will set or get the value of the discard attribute. Version 2 cookies
and response messages are only affected by this.
Example The following example aFleX script adds HttpOnly to all cookies set by
the server.
when HTTP_RESPONSE {
set current_time [TIME::clock seconds]
foreach cookie_name [HTTP::cookie names] {
if { [HTTP::cookie exists "$cookie_name"] } {
366
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example The following example closes the HTTP connection for ICAP responses if
the client's IP address is not within the specified range ([Link]/24).
when ICAP_RESPONSE {
if { not ([IP::addr [IP::client_addr] equals [Link]/24])
} {
HTTP::close
}
}
Valid Events
• HTTP_REQUEST
• HTTP_RESPONSE
• ICAP_RESPONSE
367
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
HTTP::disable
Description This command will change an HTTP proxy from full parsing to pass-
through mode.
Syntax HTTP::disable
368
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_CLIENTHELLO
• CLIENTSSL_DATA
• CLIENTSSL_HANDSHAKE
• HTTP_REQUEST
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
• SERVER_CONNECTED
• SERVERSSL_DATA
• SERVERSSL_HANDSHAKE
• SERVERSSL_SERVERHELLO
HTTP::fallback
Description This command will specify or override the fallback host that is specified
in the HTTP profile.
Example Use the following example to specify the fallback host in HTTP profile.
when LB_FAILED {
HTTP::fallback "[Link]
}
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
369
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
HTTP::header
Description This command will query for or manipulate an HTTP header.
This will return the value of the HTTP header named <name>. Drop the
<value> argument when the header name does not enter any conflicts
with subcommands.
HTTP::header names
This will return a list of all the headers present on the request or
response.
HTTP::header count
This will return the number of HTTP headers present in the request or
response.
HTTP::header at <index>
This will return the HTTP header that the ACOS device finds at the zero-
based index value.
HTTP::header exists <name>
This will return true if the named header is present on the request or
response.
HTTP::header insert ["lws"] <name> <value>
This will insert the named HTTP header and its value into the end of the
HTTP request or response. If "lws" is specified, the ACOS device adds
linear white space to long header values.
HTTP::header insert ["lws"] {n1, v1, n2, v2, n3, v3, …}
This will pass a Tcl list to insert into a header. In this situation, the
ACOS device will treat the list as a list of name/value pairs. If "lws" is
specified, the ACOS device adds linear white space to long header
values.
HTTP::header [value] <name> <string>
370
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
This will set the value of the named header. When there is a present
header, the command will replace the header; In other situations, the
command will add the header. Drop the <value> argument if the header
name does not collide with any other values.
HTTP::header replace <name> [<string>]
This will replace the last occurrence of the named header with the
string <string>. It performs a header insertion when the header was
not present.
HTTP::header remove <name>
This will remove everything except the headers specified. It does not
remove essential HTTP headers, though.
HTTP::header at <index> [nvp]
This will return the HTTP header that the ACOS device finds in at the
zero-based index value. The nvp option will return the entire header as
a name-value-pair (NVP).
HTTP::header values <name>
This will return the value or values of the HTTP header named <name>.
371
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
NOTE:
l If both HTTP::cookie and HTTP::header commands are used to modify
the same header, then HTTP::cookie takes precedence. When there is
a single value for the HTTP header, that value is returned. When
there are multiple headers with the same name, the command
returns the last value from all of them. If it is required to check all
HTTP headers that include multiple headers of the same name, use
HTTP::header at <index> nvp.
l To check if an HTTP header exists or not, use the HTTP::header
exists <name> command. For example, HTTP::header exists “foo”
will return true if an HTTP header exists and false if it doesn't exist. If
"exists" in the above command is misspelled as "exist", then ACOS
will interpret this command differently and insert a header called
"exist" with the string "foo" as HTTP::header [value] <name>
<string>.
Example Use the following example to remove all headers names with the
specified name.
when HTTP_REQUEST {
if { [HTTP::header exists "Accept-Encoding"] } {
HTTP::header remove “Accept-Encoding”
}
}
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
• ICAP_RESPONSE
HTTP::host
Description This command will return the host name of the HTTP request.
Syntax HTTP::host
372
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use the following example to return the host name of the HTTP request.
when HTTP_REQUEST {
if { [HTTP::host] starts_with "secure"} {
HTTP::redirect "[Link]
}
}
when ICAP_RESPONSE {
if { [HTTP::host] starts_with "secure"} {
HTTP::redirect "[Link]
}
}
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
• ICAP_RESPONSE
HTTP::is_keepalive
Description This command will return a true value when it is a Keep-Alive
connection.
Syntax HTTP::is_keepalive
Valid Events
373
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
HTTP::is_redirect
Description This command will return a true value if the response is a redirect of a
certain type.
Syntax HTTP::is_redirect
Example Use the following examples to log the message with a value for a
certain type of redirect.
when HTTP_RESPONSE {
if { [HTTP::is_redirect] } {
log "This is the server redirect value:"
}
}
when ICAP_RESPONSE {
if { [HTTP::is_redirect] } {
log "This is the server redirect value:"
}
}
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
• ICAP_RESPONSE
374
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
HTTP::method
Description This command will return the type of HTTP request method.
Syntax HTTP::method
Example Use the following example to log the message with a value for certain
type of redirect.
Example 1:
when HTTP_REQUEST {
log "This is the HTTP method: [HTTP::method]"
}
Example 2:
when ICAP_RESPONSE {
{
log "This is the HTTP method: [HTTP::method]"
}
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
• ICAP_RESPONSE
HTTP::password
Description Returns the password from HTTP basic authentication.
Syntax HTTP::password
Example Use the following example to return the password from HTTP basic
authentication.
[AFLEX_NSCMDID_HTTP_PASSWORD] = {
"HTTP::password",
A10Tcl_HTTP_PasswordObjCmd, A10TclCompileHTTP_
PasswordCmd,
375
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
AFLEX_VPORT_BITS_HTTP,
{0},
0
}
Valid Events
• AAM_AUTHENTICATION_INIT
• AAM_AUTHORIZATION_INIT
• AAM_AUTHORIZATION_CHECK
• AAM_RELAY_INIT
• HTTP_REQUEST
• HTTP_REQUEST_DATA
HTTP::path
Description This command will return the path part of the HTTP request.
Example Use the following examples to return the path part of the HTTP request.
when HTTP_REQUEST {
log "This is the host HTTP: [HTTP::host]"
log "This is the path of HTTP: [HTTP::path]"
}
when HTTP_REQUEST {
if { [HTTP::path] equals "/" } {
HTTP::redirect "[Link]
} else {
pool example_service-group
}
}
when ICAP_RESPONSE {
log "This is the host HTTP: [HTTP::host]"
log "This is the path of HTTP: [HTTP::path]"
376
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE_DATA
• ICAP_RESPONSE
HTTP::payload
Description This command will query for or replace content information. It allows
retrieval of content, queries for content size, or replacement for a
certain amount of content.
This will return the content that the HTTP::collect command has
collected by time of the request. If no size is specified, the system will
return the collected content.
HTTP::payload length
This will return the size of the content that the command has collected
by time of the request, but without the HTTP headers.
HTTP::payload <offset> <size>
This will return the content that the HTTP::collect command has
collected, starting at <offset> with size equals <size>.
HTTP::payload replace <offset> <size> <string>
This will replace the amount of content that is specified using the
<size> argument, starting at <offset> with <string>.
Example Use the following example to the content that the HTTP::collect
command has collected by time of the request.
when HTTP_RESPONSE {
HTTP::collect [HTTP::header Content-Length]
}
when HTTP_RESPONSE_DATA {
377
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
HTTP::query
Description This command will return the query part of the HTTP request.
Syntax HTTP::query
Example Use the following example to log the message to the query of the HTTP
request.
when HTTP_REQUEST {
log "This is the HTTP path: [HTTP::path]"
log "This is our HTTP query: [HTTP::query]"
}
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
378
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
HTTP::redirect
Description This command will redirect an HTTP request or response to the
specified URL.
NOTE: This command will send the response to the client immediately. It
cannot be specified multiple times in an aFleX script, nor can commands
that modify header or content be specified after this command, due to
its functionality.
Example Use the following example to redirect an HTTP response to the specified
URL.
when HTTP_RESPONSE {
if { [HTTP::status] == 404 } {
HTTP::redirect "[Link]
}
}
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
• ICAP_RESPONSE
HTTP::release
Description This command will release the collected data. Unless a subsequent
HTTP::collect command was issued, the HTTP::release command
inside of the HTTP_REQUEST_DATA and HTTP_RESPONSE_DATA events
is unnecessary, since in these situations, the data is implicitly released.
NOTE: This command supports old SSL (N5) and new SSL (QAT, new N5, and
Software TLS1.3).
379
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Syntax HTTP::release
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
HTTP::request
Description This command will return the raw request header string. Access the
request payload using the HTTP::collect command.
Syntax HTTP::request
Example Using this example will return the raw request header string. It uses the
HTTP::method and the HTTP version. It demonstrates the generation of
identical results for both log entries.
when HTTP_REQUEST {
log "This is the HTTP request: [HTTP::method] [HTTP::uri]
HTTP/[HTTP::version]"
log "This is the HTTP request: [HTTP::request]"
}
Valid Events
380
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
HTTP::request_num
Description This command will return the number of HTTP requests that a client
made on the connection.
Syntax HTTP::request_num
Example Use the following example to returns the number of HTTP requests that
a client made on the connection.
when HTTP_REQUEST {
log "This is the Request #: [HTTP::request_num]"
}
when ICAP_RESPONSE {
{
log "This is the Request #: [HTTP::request_num]"
}
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
• ICAP_RESPONSE
HTTP::respond
Description This command will allow users to generate or rewrite a client request or
a server response. It is a powerful API that gives users the ability to
generate or rewrite a client request or a server response
381
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Upon execution of the command on the client side, it will send the
response to the client without any load balancing taking place.
Upon execution of the command on the server side, the content from
the actual server will be discarded and replaced with information
provided to this API.
NOTE: The maximum size response for this command that can be sent is 64 KB.
NOTE: No further aFlex scripts should be run after this API due to the
functionality of this command.
Example Use the following example to generate the client request and a server
response.
Example Use of the following example sends a redirect with a cookie set.
when HTTP_REQUEST {
set cookie [format "%s=%s; path=/; domain=%s" CookieName
CookieValue ".[Link]"]
HTTP::respond 302 Location "[Link] "Set-
Cookie" $cookie
}
382
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
• ICAP_RESPONSE
HTTP::retry
Description This command will send an HTTP request to the server. It also triggers
the HTTP_REQUEST event.
Syntax HTTP:retry
NOTE: The HTTP retry command is supported only for virtual port types HTTP
and HTTPS. Fast-HTTP or other virtual port types are not supported.
Example Use the following example to send an HTTP request to the server.
when HTTP_RESPONSE {
if { [HTTP::status] == 503 } {
HTTP::retry
}
}
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
383
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
HTTP::scheme
Description This command retrieve the scheme (protocol) part of an HTTP request,
which indicates whether the request is using HTTP or HTTPS.
Syntax HTTP::scheme
Example Use the following example to check the scheme of the incoming HTTP
request and log a message indicating whether the request is secure or
not.
when HTTP_REQUEST {
set scheme [HTTP::scheme]
if { $scheme eq "http" } {
log "Insecure HTTP request received"
}
}
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
HTTP::status
Description This command will return the response status code.
Syntax HTTP::status
Example Use the following example to return the HTTP response status code.
when HTTP_RESPONSE {
if { [HTTP::status] == 404 } {
HTTP::redirect "[Link]
}
}
Example Use the following example to return the ICAP response status code.
when ICAP_RESPONSE {
384
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
if { [HTTP::status] == 404 } {
HTTP::redirect "[Link]
}
}
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
• ICAP_RESPONSE
HTTP::stream
Description This command will replace the specified string of an HTTP response.
Example Use the following example to replace the specified string of an HTTP
response.
when HTTP_RESPONSE {
HTTP::stream replace "Internal Site" "Public Site"
HTTP::stream replace "[Link] "[Link]
}
Example Use the following example to replace the specified string of an ICAP
response.
385
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
when ICAP_RESPONSE {
HTTP::stream replace "Internal Site" "Public Site"
HTTP::stream replace "[Link] "[Link]
}
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
HTTP::uri
Description This command will return or set the URI of the request. This command
replaces the http_uri command.
This will change the URI passed to the server. Check that it starts with a
slash. The URI string does not include the http or https protocol or
hostname.
Example Use the following example to change the URI passed to the server.
when HTTP_REQUEST {
if { [HTTP::uri] ends_with ".html" } {
pool service_group_static
} elseif { [HTTP::uri] ends_with ".asp" } {
pool service_group_dynamic
}
}
Example Use the following example to change the URI passed to the ICAP
response.
when ICAP_RESPONSE {
if { [HTTP::uri] ends_with ".html" } {
pool service_group_static
} elseif { [HTTP::uri] ends_with ".asp" } {
386
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
pool service_group_dynamic
}
}
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• ICAP_RESPONSE
HTTP::username
Description This command will returns the username from HTTP basic
authentication..
Syntax HTTP:username
Example Use the following example to return the username from HTTP basic
authentication.
when HTTP_REQUEST {
if {[HTTP::username] eq "admin"} {
log "Admin user accessed"
}
}
Valid Events
• AAM_AUTHENTICATION_INIT
• AAM_AUTHORIZATION_INIT
• AAM_AUTHORIZATION_CHECK
• AAM_RELAY_INIT
• HTTP_REQUEST
• HTTP_REQUEST_DATA
HTTP::version
Description This command will return or set the HTTP version of the request or
response. It replaces the http_version command.
387
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use the following example to sets the HTTP version of the response.
when HTTP_RESPONSE {
log "This is the version of HTTP: [HTTP::version]"
}
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
388
ICAP Commands
The following IP commands are supported:
l ICAP::disable
l ICAP::header add
l ICAP::header remove
l ICAP::header values
l ICAP::header replace
l ICAP::header replace-all
l ICAP::method
l ICAP::status
l ICAP::respmod_valid
l ICAP::reqmod_valid
l ICAP::uri
389
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
ICAP::disable
Description This command will disable ICAP for certain requests, based on the HTTP
headers.
Syntax ICAP::disable
Example Use of the following example selects a specific pool for a specific client
IP address.
when HTTP_REQUEST {
set method [HTTP::method]
if { ($method matches "POST")
or ($method matches "PUT") } {
return // follow the ICAP policy configured with CLI
} else {
ICAP::disable // disable ICAP template policy
}
}
Valid Events
• HTTP_REQUEST
• HTTP_RESPONSE
ICAP::header add
Description This command inserts a header to ICAP reqmod/respmod packet
NOTE: For singleton attributes only the first one added will appear in traffic.
For others, values will be separated by comma.
390
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
• ICAP_REQUEST
ICAP::header remove
Description This command will remove default, non-default, and previously header
values.
Valid Events
• ICAP_REQUEST
ICAP::header replace
Description The replace and add command are similar except that replace will not
append value to list, it will replace the existing values.
Example Use the following example to replace the specified header with given
value.
when ICAP_REQUEST {
ICAP::header replace Preview 2
391
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
• ICAP_REQUEST
ICAP::header replace-all
Description This command will replace existing header values.
Example Use the following example to replace the whole header with given text.
when ICAP_REQUEST {
ICAP::header replace-all "Host: [Link]:1344\r\nDate:
Tue, 28-May-2019 09:17:50 GMT\r\nEncapsulated:
req-hdr=0, req-body=147\r\nPreview: 1\r\nAllow:
204\r\nX-Client-IP: [Link]\r\nX-Server-IP: [Link]\r\n"
ICAP::header add X-DEF abc
}
Valid Events
• ICAP_REQUEST
ICAP::header values
Description This command can get a header value from ICAP reqmod/respmod
response.
Example Use the following example to get a header value from ICAP respmod.
when ICAP_RESPONSE {
log " ISTag header value is [ICAP::header values ISTag]"
}
392
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
• ICAP_RESPONSE
ICAP::method
Description This command returns ICAP request method which can be reqmod or
respmod.
Syntax ICAP::method
Example Use the following example to return the method of this request.
when ICAP_REQUEST {
log "method [ICAP::method]"
log "get uri [ICAP::uri]"
}
Valid Events
• ICAP_REQUEST
ICAP::reqmod_valid
Description This command will check if reqmod-icap template is bound under the
vPort and the ICAP service used is active. Return 1 only when reqmod-
icap template is bound and the ICAP service used is active; otherwise,
return 0.
Syntax ICAP::reqmod_valid
Example Use the following example to check that vport has reqmod configured
and that it is not disabled.
when HTTP_REQUEST {
log "req [ICAP::reqmod_valid]"
}
Valid Events
393
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• HTTP_REQUEST
• HTTP_REQUEST_DATA
ICAP::respmod_valid
Description This command will check if respmod-icap template is bound under the
vPort and the ICAP service used is active. Return 1 only when respmod-
icap template is bound and the ICAP service used is active; otherwise,
return 0.
Syntax ICAP::respmod_valid
Example Use the following example to check that vport has respmod configured
and that it is not disabled.
when HTTP_RESPONSE {
log "resp [ICAP::respmod_valid]"
}
Valid Events
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
ICAP::status
Description This command will get ICAP response status code.
Syntax ICAP::status
Example Use the following example to return the status code of the response.
when ICAP_RESPONSE {
log "status [ICAP::status]"
}
Valid Events
• ICAP_RESPONSE
394
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
ICAP::uri
Description This command will set or return ICAP service URI sent to ICAP server.
Syntax ICAP::uri
Example Use the following example to get the uri of the request.
when ICAP_REQUEST {
ICAP::uri icap://A10icap:1344/echo
}
Valid Events
• ICAP_REQUEST
395
IP Commands
The following topics are covered in this section:
l IP::addr
l IP::category
l IP::client_addr
l IP::local_addr
l IP::protocol
l IP::remote_addr
l IP::reputation
l IP::server_addr
l IP::stats
l IP::tos
l IP::ttl
l IP::version
396
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
IP::addr
Description This command will compare IP address/subnet/supernet to IP
address/subnet/supernet. It returns 0 if there is no match, and 1 in case
there is a match.
NOTE: The IP::addr command does not perform a string comparison. If a literal
string comparison is needed, compare the 2 strings with the
appropriate operator (for example, equals, contains, starts_with)
instead of using this command.
Example Use of the following example selects a specific pool for a specific client
IP address.
when CLIENT_ACCEPTED {
if { [IP::addr [IP::client_addr] equals [Link]] } {
pool example_service_group
}
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• HTTP_REQUEST
397
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• CLIENT_DATA
• SERVER_DATA
IP::category
Description This command fetches the IP category from a local database.
A TCL contains the following category list:
• spam-sources
• windows-exploits
• web-attacks
• botnets
• scanners
• dos-attacks
• reputation
• phishing
• proxy
• mobile-threats
• tor-proxy
• uncategorized
Syntax IP::category IP
398
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use the following example to return the IP category string from threat-
intel local database.
when HTTP_REQUEST {
set local_ip [IP::local_addr]
set cat_list [IP::category $local_ip]
foreach cat $cat_list {
log "IP category: $cat"
}
}
Valid Events
• CLIENT_ACCEPTED
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• DNS_REQUEST
• DNS_RESPONSE
IP::client_addr
Description This command will return the client IP address of a connection. It is the
same as using the command clientside { IP::remote_addr }.
Syntax IP::client_addr
Example Use the following example to select a specific service group for a
specific client IP address.
when CLIENT_ACCEPTED {
if { [IP::addr [IP::client_addr] equals [Link]] } {
pool example_service_group
}
}
Valid Events
• CLIENT_ACCEPTED
399
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• CLIENT_CLOSED
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• CLIENT_DATA
• SERVER_DATA
IP::local_addr
Description This command is useful for addressing generic rules that are reused. It
is also useful in reusing the connected endpoint in another statement
or in making routing type decisions. The IP::client_addr and
IP::server_addr commands can also be specified.
Syntax IP::local_addr
This will return the IP address of the ACOS being used in the
connection. From the clientside position, this is the destination IP
address (virtual IP address). From the serverside position, this is the
source IP address. The following example shows the SNAT address if
SNAT is used, otherwise it spoofs client IP address).
Example Use the following example to select a specific service group for a
specific virtual IP address.
when CLIENT_ACCEPTED {
if { [IP::addr [IP::local_addr] equals [Link]] } {
pool service_group_internal
} else {
pool example_service_group
}
}
400
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• CLIENT_DATA
• SERVER_DATA
IP::payload
Description This command is used to directly access or modify the IP layer payload.
Syntax IP::payload
The IP address for which the payload needs to be fetched from the
database.
Example Use the following example to log the raw IP payload data received from
the client:
when CLIENT_DATA {
set payload [IP::payload]
log "Raw IP Payload: $payload"
}
401
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
IP::protocol
Description This command will return the IP protocol value.
Syntax IP::protocol
Example Use the following example to select a specific service group based on IP
protocol version.
when CLIENT_ACCEPTED {
if { [IP::protocol] == 6 } {
pool service_group_tcp
} else {
pool service_group_udp
}
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• CLIENT_DATA
• SERVER_DATA
IP::remote_addr
Description This command will return the IP address of the host at the far end of
the connection. From the clientside position, this is the client IP
address. From the serverside position, this is the node IP address. The
402
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Syntax IP::remote_addr
Example Use the following example to select a specific service group for a
specific client IP address. Then log the server address of the real server
where the request is to be forwarded.
when CLIENT_ACCEPTED {
if { [IP::addr [IP::remote_addr] equals [Link]] } {
pool example_service_group
}
}
when SERVER_CONNECTED {
log "This is the node IP address [IP::remote_addr]
assigned to [IP::client_addr]"
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• CLIENT_DATA
• SERVER_DATA
IP::reputation
Description This command fetches the IP reputation value from a local database. It
can display one of the following values:
403
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Syntax IP::reputation IP
NOTE: There are only 'high risk' records in the local database.
Example Use the following example to returns the IP reputation value from local
database.
when HTTP_REQUEST {
set local_ip [IP::local_addr]
log "Access Server $local_ip (reputation: [IP::reputation
$local_ip])"
}
Valid Events
• CLIENT_ACCEPTED
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• DNS_REQUEST
• DNS_RESPONSE
IP::server_addr
Description This command will return the server’s (node’s) IP address, after a server
side connection has been established. It is the same as using the server
404
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Syntax IP::server_addr
Example Use the following example to log the end node or the real server
address.
when SERVER_CONNECTED {
log "This is the node IP address [IP::server_addr]"
}
Valid Events
• CLIENT_CLOSED
• CLIENT_DATA
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
IP::stats
Description This command will supply information regarding the number of packets
or bytes being sent or received in a given connection.
405
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use the following example to log the total received packets for the
connection.
when CLIENT_CLOSED {
log "Total received packets: [IP::stats pkts in]"
}
Valid Events
• All.
• For information about aFleX events, see aFleX Events.
IP::tos
Description This command will select a different pool of servers based on the Type
of Service (ToS) level within a packet. The ToS standard is one method
where network equipment can identify and treat traffic differently
based on an identifier. As soon as traffic enters the site, the ACOS
device can apply a rule that sends traffic to different pools of servers
based on the ToS level within a packet.
Syntax IP::tos
This will select a different pool of servers based on the ToS level within
a packet.
Example Use the following example to select a specific pool based on TOS level
in the packet.
when CLIENT_ACCEPTED {
if { [IP::tos] == 16 } {
pool service_group_priority
} else {
pool example_service_group
}
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• HTTP_REQUEST
406
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• CLIENT_DATA
• SERVER_DATA
IP::ttl
Description This command will return the TTL of the current packet being acted
upon.
Syntax IP::ttl
Example Use the following example to drop the connection if the TTL for the
packet is below 3.
when CLIENT_ACCEPTED {
if { [IP::ttl] < 3 } {
drop
}
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
• LB_SELECTED
407
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• SERVER_CLOSED
• SERVER_CONNECTED
• CLIENT_DATA
• SERVER_DATA
IP::version
Description This command will return the version of the current packet being acted
upon.
Syntax IP::version
Example Use the following example to select a specific service group based on IP
protocol version.
when CLIENT_ACCEPTED {
if { [IP::version] == 6 } {
pool service_group_ipv6
} else {
pool service_group_ipv4
}
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• CLIENT_DATA
• SERVER_DATA
408
Limit ID Commands
The following Limit ID (LID) commands are supported:
l LID::conn_limit
l LID::conn_rate_limit
l LID::exists
l LID::nat_pool
l LID::request_limit
l LID::request_rate_limit
l LID::type
NOTE: Multiple LID definitions may be available for a non-global LID. This
includes a LID in a policy template bound to a virtual port, a LID in DNS
template bound to a virtual port, a LID in a policy template bound to a
virtual server, and a LID configured in a system-wide policy template.
NOTE: To apply these commands, the LID must be configured and attached to
the same virtual port as the aFleX policy using the template. If GLID is
used, it must be configured and enabled on the configuration.
409
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
LID::conn_limit
Description Returns a list of conn-limit and LID type, each one for a matching LID
where conn-limit is configured.
Example Use the following example to log the connection limit specified for LID
1.
when HTTP_REQUEST {
log "The LID connection limit for LID1 is [LID::conn_limit
lid1]"
}
Valid Events
• CACHE_REQUEST
• CACHE_RESPONSE
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
• DNS_REQUEST
• DNS_RESPONSE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• LB_FAILED
• LB_SELECTED
• SERVER_CLOSED
410
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• SERVER_CONNECTED
• SERVER_DATA
• SIP_REQUEST
• SIP_REQUEST_SEND
• SIP_RESPONSE
LID::conn_rate_limit
Description Returns a list of conn-rate-limit values and LID type, one each for a
matching LID where conn-rate-limit is configured.
Example Use the following example to log the connection rate limit specified for
GLID 1.
when HTTP_REQUEST {
log "The LID connection rate limit for glid1 is
[LID::conn_rate_limit glid1]"
}
Valid Events
• CACHE_REQUEST
• CACHE_RESPONSE
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
• DNS_REQUEST
• DNS_RESPONSE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
411
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• LB_FAILED
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
• SIP_REQUEST
• SIP_REQUEST_SEND
• SIP_RESPONSE
LID::exists
Description Returns a Boolean value that indicates whether the specified LID exists.
Example Use the following example to log the presence of the specified GLID.
when HTTP_REQUEST {
log "The LID exists for glid1 [LID::exists glid1]"
}
Valid Events
• CACHE_REQUEST
• CACHE_RESPONSE
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
• DNS_REQUEST
• DNS_RESPONSE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
412
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• LB_FAILED
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
• SIP_REQUEST
• SIP_REQUEST_SEND
• SIP_RESPONSE
LID::nat_pool
Description Returns a list of string and LID type, one each for a matching LID where
nat-pool is configured.
Example Use the following example to log the NAT pool associated with GLID 1.
when HTTP_REQUEST {
log "The LID NAT pool for glid1 is [LID::nat_pool glid1]"
}
Valid Events
• CACHE_REQUEST
• CACHE_RESPONSE
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
• DNS_REQUEST
413
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• DNS_RESPONSE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• LB_FAILED
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
• SIP_REQUEST
• SIP_REQUEST_SEND
• SIP_RESPONSE
LID::request_limit
Description Returns a list of request-limit and LID type, one each for a matching LID
where request-limit is configured.
Example Use the following example to log the request limit specified for GLID 1.
when HTTP_REQUEST {
log "The LID request limit for glid1 is [LID::request_
limit glid1]"
}
Valid Events
• CACHE_REQUEST
• CACHE_RESPONSE
• CLIENT_ACCEPTED
• CLIENT_CLOSED
414
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• CLIENT_DATA
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
• DNS_REQUEST
• DNS_RESPONSE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• LB_FAILED
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
• SIP_REQUEST
• SIP_REQUEST_SEND
• SIP_RESPONSE
LID::request_rate_limit
Description Returns a list of request-rate-limit values and LID type, one each for a
matching LID where conn-rate-limit is configured.
Example Use the following example to log the request rate limit specified for
GLID 1.
when HTTP_REQUEST {
log "The LID request rate limit for glid is [LID::request_
rate_limit glid1]"
}
415
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
• CACHE_REQUEST
• CACHE_RESPONSE
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
• DNS_REQUEST
• DNS_RESPONSE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• LB_FAILED
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
• SIP_REQUEST
• SIP_REQUEST_SEND
• SIP_RESPONSE
LID::type
Description Returns a list of LIDs of the specified type.
416
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use this example to return a list of LID types, one each for a matching
LID. The type can be one of the following: global, vport-policy, vport-
dns, vserver-policy, system-policy.
when HTTP_REQUEST {
log "The glid1 type is [LID::type glid1]"
}
Valid Events
• CACHE_REQUEST
• CACHE_RESPONSE
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
• DNS_REQUEST
• DNS_RESPONSE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• LB_FAILED
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
• SIP_REQUEST
• SIP_REQUEST_SEND
• SIP_RESPONSE
417
Link Commands
The following link commands are supported:
l LINK::lasthop
l LINK::nexthop
l LINK::vlan_id
418
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
LINK::lasthop
Description Returns the MAC address of the last hop.
Syntax LINK::lasthop
Example Use the following example to return the MAC address of the last hop.
when HTTP_REQUEST {
log "The LID request rate limit for glid1 is
[LID::request_rate_limit glid1]"
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
LINK::nexthop
Description Returns the MAC address of the next hop.
Syntax LINK::nexthop
Example Use the following example to return the MAC address of the next hop.
when SERVER_CONNECTED {
log "The Ethernet is { [LINK::lasthop] to [LINK::nexthop]
tag is [LINK::vlan_id] }"
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
419
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• CLIENT_DATA
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
LINK::vlan_id
Description Returns the VLAN tag of the packet. In some cases, the VLAN ID may be
unavailable. In these cases a value of 0 will be returned.
Syntax LINK::vlan_id
Example Use the following example to return the VLAN tag of the packet.
when CLIENT_ACCEPTED {
set log_message "Client is { [IP::client_addr]:
[TCP::client_port] -> [IP::local_addr]:[TCP::local_port] }"
append log_message " Ethernet is { [string range
[LINK::lasthop] 0 16] -> [string range [LINK::nexthop] 0 16]"
append log_message " Tag is [LINK::vlan_id] }"
log "$log_message"
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
420
Load-balancing Commands
The following load-balancing (LB) commands are supported:
l LB::down
l LB::reselect
l LB::server
l LB::status
421
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
LB::down
Description Temporarily marks the current real port down for 30 seconds.
Syntax LB::down
Valid Events
• LB_FAILED
• LB_SELECTED
LB::reselect
Description Reperforms server selection.
Causes SLB to select the next available member (server and port) from
the same service group used for the initial server selection. To specify
the service group to use, use the pool <pool-name> option. If you also
use the <member> option, the specified member is selected from the
specified service group.
NOTE: This command applies to Layer 7 traffic only for HTTP and HTTPS.
NOTE: Failure to execute this command will not always trigger the LB_FAILED
event.
NOTE: Server template limits are applied for both service-group and server
selection. Commands that call for server selection (i.e., node, pool,
persist, etc.) will enforce server template limits on the selected server.
As a result, new connections that match a persist uie entry may be
unable to use the rport and a default server selection will occur
instead. To prevent default server selection, use the no def-selection-if-
pref-failed command for the virtual port.
422
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example In this aFleX policy, the HTTP::retry command retries sending a client’s
request to a service port that replies with an HTTP 5xx status code. If
the first server continues to reply with a 5xx status code after 3 retries,
the LB::reselect command reassigns the client request to another
server.
when CLIENT_ACCEPTED {
set retry 0
set max_retry 3
set reselect 0
}
when LB_SELECTED {
if { $retry > 0 } {
LB::reselect
incr reselect
}
}
when HTTP_RESPONSE {
if { $retry < $max_retry } {
if { [HTTP::status] starts_with "5" } {
incr retry
}
}
}
Example This aFleX policy is similar to the one above, except the LB::down
command in the policy marks the service port down for 30 seconds.
when CLIENT_ACCEPTED {
set retry 0
set max_retry 3
}
when HTTP_REQUEST {
log "HTTP_REQUEST: Retry Count: $retry"
}
when LB_SELECTED {
log "LB_SELECTED: Current Retry Count: $retry"
if { $retry > 0 } {
log "LB::reselect"
LB::down
423
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
LB::reselect
}
}
when HTTP_RESPONSE {
log "HTTP_RESPONSE: [HTTP::status]"
if { $retry < $max_retry } {
if { [HTTP::status] starts_with "5" } {
log "HTTP::retry"
incr retry
HTTP::retry
}
}
}
Valid Events
• LB_FAILED
• LB_SELECTED
LB::server
Description Returns the results of pool and node selection.
Syntax LB::server
Returns a Tcl list containing the pool, node, node IP address, and Layer
4 protocol port selected by SLB. If no server was selected when the
script was executed, or all servers are down, the command returns only
the default pool name.
LB::server pool
424
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Returns the name of the server with the specified IPv4 or IPv6 address.
Returns an empty string if no server with the specified IP address
exists.
Example The following example shows a script that replaces the Host header
with a header that contains the backend server’s hostname:
when LB_SELECTED {
switch [LB::server addr] {
"[Link]" { HTTP::header replace Host
[Link] }
"[Link]" { HTTP::header replace Host
[Link] }
}
}
Example This examples shows a script which checks if the default pool has less
than 2 active members.
when HTTP_REQUEST {
if { [active_members [LB::server pool]] < 2 } {
HTTP::respond 200 content "We are sorry, but the site
you are looking for is temporarily out of service."
}
}
425
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example The following example show a script that logs server names with their
associated IP addresses.
when CLIENT_DATA {
log "The LB Server resolve of [Link] is [LB::server
resolve addr [Link]]"
log "The LB server resolve of rs1 is [LB::server resolve
name rs1]"
log "[LB::server resolve addr 2001:DB8::a10]"
log "[LB::server resolve name rs1]"
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
• LB_FAILED
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
NOTE: The LB::server resolve [addr] option is valid with all events.
LB::status
Description Returns the health check status (up or down) of a node or pool.
If you were to specify the node IP address only, the Layer 3 health
status of the server is returned. If you also specify a protocol port and
426
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
its transport protocol, the health status of the port is also returned. If
you use the port option, the port number and the transport protocol
are required.
LB::status pool <pool_name>
Example Use the following example to check the health check status of a node.
when HTTP_REQUEST {
if { [LB::status node [Link] port 80 tcp] equals
"up" } {
log "node [Link] port 80 is UP!"
} else {
log "node [Link] port 80 is DOWN!"
}
}
Example Use the following example to check the health status of the service
group.
when HTTP_REQUEST {
if { [LB::status pool example_service_group [Link]
80] equals "up" } {
log "The member [Link] port 80 of service group
example_service_group is UP!"
} else {
log "The member [Link] port 80 of service group
example_service_group is DOWN!"
}
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
427
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• CLIENT_DATA
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
• LB_FAILED
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
428
MQTT Commands
The following MQTT commands supported are:
l MQTT::clean_session_flag
l MQTT::client_id
l MQTT::collect
l MQTT::drop
l MQTT::dup_flag
l MQTT::keep_alive
l MQTT::length
l MQTT::packet_id
l MQTT::password
l MQTT::payload
l MQTT::payload_length
l MQTT::protocol_name
l MQTT::protocol_version
l MQTT::qos
l MQTT::replace
l MQTT::respond
l MQTT::retain_flag
l MQTT::return_code
l MQTT::return_code_list
l MQTT::session_present_flag
l MQTT::topic
l MQTT::type
429
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
l MQTT::username
l MQTT::will
NOTE:
l Default and Client_id based load balancing methods are supported
on MQTT [Link]-hash-persist first N: Use the first N bytes for
server [Link]-hash-persist last N: Use the last N bytes for
server selection.
l Clientid-hash-persist offset N: Start from Nth bytes of the client id.
l Must be used together with first or last option.
l aFleX processes a message within 1MB only.
l For bigger messages, aFleX forwards the message successfully, but
only prints message contents and flags up to 1MB. For example:
- If an MQTT CONNECT message is with a large will-topic
(example:2000 bytes) following with a will-message, aFleX prints the
will-topic up to 1 MB only.
- If the field or flag does not exist, then the output value is -1, so that
users can detect the situation.
430
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
MQTT::clean_session_flag
Description Gets the flag for an MQTT CONNECT message.
Syntax MQTT::clean_session_flag
Example Uses the following example to log the clean session flag value.
when MQTT_CLIENT_MESSAGE {
log “[MQTT::clean_session_flag]”
Valid Events
• MQTT_CLIENT_MESSAGE
• MQTT_CLIENT_MESSAGE_DATA
• MQTT_SERVER_MESSAGE
• MQTT_SERVER_MESSAGE_DATA
MQTT::client_id
Description Gets the client identifier for an MQTT CONNECT message.
Syntax MQTT::client_id
Valid Events
• MQTT_CLIENT_MESSAGE
• MQTT_CLIENT_MESSAGE_DATA
• MQTT_SERVER_MESSAGE
• MQTT_SERVER_MESSAGE_DATA
MQTT::collect
Description Collects at least bytes of payload
431
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Syntax MQTT::collect
Collect the entire payload of the MQTT message or the maximum length
of the payload (which is 1MB). If the message is longer than 1MB, the
processing can only be done on the first 1MB.
MQTT::collect <size>
when MQTT_CLIENT_MESSAGE_DATA {
if { [MQTT::type] equals 8} {
log "payload in PUBLISH is [MQTT::payload]"
}
}
Valid Events
• MQTT_CLIENT_MESSAGE
• MQTT_SERVER_MESSAGE
MQTT::drop
Description Drop the current MQTT message
Syntax MQTT::drop
Example Use the following example to drop the MQTT message from the server
side which includes "5min" in its topic:
when MQTT_SERVER_MESSAGE {
if { [MQTT::topic] contains "5min" } {
MQTT::drop
}
}
432
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
• MQTT_CLIENT_MESSAGE
• MQTT_CLIENT_MESSAGE_DATA
• MQTT_SERVER_MESSAGE
• MQTT_SERVER_MESSAGE_DATA
MQTT::dup_flag
Description Gets the duplicate flag for an MQTT PUBLISH message.
Syntax MQTT::dup_flag
Example Use the following example to log the dup flag value.
when MQTT_CLIENT_MESSAGE {
log “[MQTT::dup_flag]”
}
Valid Events
• MQTT_CLIENT_MESSAGE
• MQTT_CLIENT_MESSAGE_DATA
• MQTT_SERVER_MESSAGE
• MQTT_SERVER_MESSAGE_DATA
MQTT::keep_alive
Description Gets the keep_alive field for an MQTT CONNECT message.
Syntax MQTT::keep_alive
Valid Events
• MQTT_CLIENT_MESSAGE
433
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• MQTT_CLIENT_MESSAGE_DATA
• MQTT_SERVER_MESSAGE
• MQTT_SERVER_MESSAGE_DATA
MQTT::length
Description Gets the length for an MQTT message.
Syntax MQTT::length
Example Use the following example to log the length for an MQTT message.
when MQTT_CLIENT_MESSAGE {
log “[MQTT::length]”
}
Valid Events
• MQTT_CLIENT_MESSAGE
• MQTT_CLIENT_MESSAGE_DATA
• MQTT_SERVER_MESSAGE
• MQTT_SERVER_MESSAGE_DATA
MQTT::packet_id
Description Gets the packet-id for an MQTT message and sets the packet-id of the
MQTT message to the given value and the value range is [0 to 65535].
Syntax MQTT::packet_id
MQTT::packet_id <packet-id>
Example Use the following examples to log the packet Id for an MQTT message.
when MQTT_CLIENT_MESSAGE {
log “[MQTT::packet_id]”
}
when MQTT_CLIENT_MESSAGE {
MQTT::packet_id -1
434
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
MQTT::packet_id 1 1
}
Valid Events
• MQTT_CLIENT_MESSAGE
• MQTT_CLIENT_MESSAGE_DATA
• MQTT_SERVER_MESSAGE
• MQTT_SERVER_MESSAGE_DATA
MQTT::password
Description Gets the password field for an MQTT CONNECT message.
Syntax MQTT:password
Valid Events
• MQTT_CLIENT_MESSAGE
• MQTT_CLIENT_MESSAGE_DATA
• MQTT_SERVER_MESSAGE
• MQTT_SERVER_MESSAGE_DATA
MQTT::payload
Description Gets the payload of an MQTT PUBLISH message
Syntax MQTT::payload
435
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
payload starting from offset to offset + size with the given content
MQTT::payload prepend <content> - Add the given content to the
beginning of the payload
MQTT::payload append <content> - Add the given content to the end
of the payload
Example Use the following example to log the payload of an MQTT PUBLISH
message.
when MQTT_CLIENT_MESSAGE_DATA {
log “[MQTT::payload]”
}
Example Use the following example to log the payload of an MQTT replace,
prepend, append message.
when MQTT_CLIENT_MESSAGE_DATA {
MQTT::payload replace test
MQTT::payload prepend test:
MQTT::payload append :test
log "[MQTT::payload]"
}
Example Use the following example to log the payload of an MQTT replace
message.
when MQTT_CLIENT_MESSAGE_DATA {
MQTT::payload replace 5 10 aflex_data
}
Valid Events
• MQTT_CLIENT_MESSAGE
• MQTT_CLIENT_MESSAGE_DATA
• MQTT_SERVER_MESSAGE
• MQTT_SERVER_MESSAGE_DATA
MQTT::payload_length
Description Gets the payload length for an MQTT PUBLISH message.
436
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Syntax MQTT::payload_length
Example Use the following example to log the payload length for an MQTT
PUBLISH message
when MQTT_CLIENT_MESSAGE_DATA {
log “[MQTT::payload_length]”
}
Valid Events
• MQTT_CLIENT_MESSAGE
• MQTT_CLIENT_MESSAGE_DATA
• MQTT_SERVER_MESSAGE
• MQTT_SERVER_MESSAGE_DATA
MQTT::protocol_name
Description Gets the protocol name for an MQTT CONNECT message.
Syntax MQTT::protocol_name
Example Use the following example to log the protocol name for an MQTT
message.
when MQTT_CLIENT_MESSAGE {
log “[MQTT::protocol_name]”
}
Valid Events
• MQTT_CLIENT_MESSAGE
• MQTT_CLIENT_MESSAGE_DATA
• MQTT_SERVER_MESSAGE
• MQTT_SERVER_MESSAGE_DATA
MQTT::protocol_version
Description Gets the protocol review level for an MQTT CONNECT message.
437
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Syntax MQTT::protocol_version
Example Use the following example to log the protocol version for an MQTT
message.
when MQTT_CLIENT_MESSAGE {
log “[MQTT::protocol_version]”
}
Valid Events
• MQTT_CLIENT_MESSAGE
• MQTT_CLIENT_MESSAGE_DATA
• MQTT_SERVER_MESSAGE
• MQTT_SERVER_MESSAGE_DATA
MQTT::qos
Description Gets the Quality of Services (QoS) for an MQTT PUBLISH message.
Supports the following three types of QoS:
• At most once
• At least once
• Exactly once
438
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Syntax MQTT::qos
Example Use the following examples to log the QoS for an MQTT message:
when MQTT_CLIENT_MESSAGE {
log “[MQTT::qos]”
}
when MQTT_PUBLISH {
set old_qos [MQTT::qos]
log "In MQTT_PUBLISH event, initial qos=[MQTT::qos], packet_
id=[MQTT::packet_id] "
if {$old_qos==0 } {
MQTT::packet_id [expr {int (rand()*65000)}]
}
MQTT::qos 2
log "After setting qos as 2, the new qos = [MQTT::qos],
packet_
id=[MQTT::packet_id] "
}
Valid Events
• MQTT_CLIENT_MESSAGE
• MQTT_CLIENT_MESSAGE_DATA
• MQTT_SERVER_MESSAGE
• MQTT_SERVER_MESSAGE_DATA
MQTT::replace
Description This command replaces an MQTT message.
Example Use the following example to replace the current MQTT message.
when MQTT_CLIENT_MESSAGE {
439
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
• MQTT_CLIENT_MESSAGE
• MQTT_CLIENT_MESSAGE_DATA
• MQTT_SERVER_MESSAGE
• MQTT_SERVER_MESSAGE_DATA
MQTT::respond
Description This command transmits an MQTT message to sender of the incoming
message.
Valid Events
• MQTT_CLIENT_MESSAGE
• MQTT_CLIENT_MESSAGE_DATA
• MQTT_SERVER_MESSAGE
• MQTT_SERVER_MESSAGE_DATA
440
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
MQTT::retain_flag
Description Gets the retain flag for an MQTT PUBLISH message
Syntax MQTT::retain_flag
Example Use the following example to log the retain flag value for an MQTT
message.
Example 1 - MQTT::retain_flag
when MQTT_CLIENT_MESSAGE_DATA {
log “[MQTT::retain_flag]”
}
Example Use the following example to get retain flag for an MQTT message.
when MQTT_SERVER_MESsAGE {
MQTT::retain_flag 0
}
Valid Events
• MQTT_CLIENT_MESSAGE
• MQTT_CLIENT_MESSAGE_DATA
• MQTT_SERVER_MESSAGE
• MQTT_SERVER_MESSAGE_DATA
MQTT::return_code
Description Gets the return-code field for an MQTT CONNACK message.
Syntax MQTT::return_code
Example Use the following example to log the return code for an MQTT message.
when MQTT_SERVER_MESSAGE_DATA {
441
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
log “[MQTT::return_code]”
}
Valid Events
• MQTT_CLIENT_MESSAGE
• MQTT_CLIENT_MESSAGE_DATA
• MQTT_SERVER_MESSAGE
• MQTT_SERVER_MESSAGE_DATA
MQTT::return_code_list
Description Gets the return-code-list for multiple MQTT SUBACK messages.
Syntax MQTT::return_code_list
Example Use the following example to log the return code list for multiple MQTT
messages.
when MQTT_SERVER_MESSAGE_DATA {
log “[MQTT::return_code_list]”
}
Valid Events
• MQTT_CLIENT_MESSAGE
• MQTT_CLIENT_MESSAGE_DATA
• MQTT_SERVER_MESSAGE
• MQTT_SERVER_MESSAGE_DATA
MQTT::session_present_flag
Description Gets the session_present flag for an MQTT CONNACK message.
Syntax MQTT::session_present_flag
Example Use the following example to log the value of session present flag for
an MQTT message.
when MQTT_SERVER_MESSAGE_DATA {
442
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
log “[MQTT::session_present_flag]”
}
Valid Events
• MQTT_CLIENT_MESSAGE
• MQTT_CLIENT_MESSAGE_DATA
• MQTT_SERVER_MESSAGE
• MQTT_SERVER_MESSAGE_DATA
MQTT::topic
Description Get the list of the topic names from SUBSCRIBE/UNSUBSCRIBE message,
or the topic name from PUBLISH message.
Syntax MQTT::topic
443
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use the following example to log the topic for an MQTT message.
when MQTT_CLIENT_MESSAGE {
log “[MQTT::topic]”
}
Example Use the following example to get topics from an MQTT PUBLISH
message.
when MQTT_CLIENT_MESSAGE_DATA{
MQTT::topic replace test300
}
when MQTT_SERVER_MESSAGE_DATA {
log "[MQTT::topic count]"
log "[MQTT::topic]"
log "[MQTT::topic index 0]"
log "[MQTT::topic qos test]"
log "[MQTT::topic add test100 2]"
}
Valid Events
• MQTT_CLIENT_MESSAGE
• MQTT_CLIENT_MESSAGE_DATA
• MQTT_SERVER_MESSAGE
• MQTT_SERVER_MESSAGE_DATA
MQTT::type
Description Gets the type for an MQTT message. The following are the message
types:
• Reserved (0):
• CONNECT (1): When a client requests to connect to a server.
• CONNACK ( 2): When a server acknowledges the connection from a
client.
• PUBLISH 3 (3): When the server publishes a message.
444
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Syntax MQTT::type
Example Use the following example to log the type for an MQTT message.
when MQTT_CLIENT_MESSAGE {
log “[MQTT::type]”
}
Valid Events
• MQTT_CLIENT_MESSAGE
• MQTT_CLIENT_MESSAGE_DATA
• MQTT_SERVER_MESSAGE
• MQTT_SERVER_MESSAGE_DATA
MQTT::username
Description Gets the username field for an MQTT CONNECT message.
445
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Syntax MQTT::username
Example Use the following example to log the username included in an MQTT
message.
when MQTT_CLIENT_MESSAGE {
log “[MQTT::username]”
}
Valid Events
• MQTT_CLIENT_MESSAGE
• MQTT_CLIENT_MESSAGE_DATA
• MQTT_SERVER_MESSAGE
• MQTT_SERVER_MESSAGE_DATA
MQTT::will
Description Gets and sets the parts of the will message for an MQTT Connect
message in the following sequence:
• will-topic
• will-message
• will-qos
• will-retain flag
• will-flag
446
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
message
MQTT::will will-retain-flag <will-retain> - Set the will-retain
value to be the given value. The given value must reside within [0, 1]
Example Use the following example to get the will message for an MQTT Connect
message.
when MQTT_CLIENT_MESSAGE {
MQTT::will will-topic aflexTest
MQTT::will will-message aflexTest
MQTT::will will-qos 0
MQTT::will will-retain-flag 0
}
Valid Events
• MQTT_CLIENT_MESSAGE
• MQTT_CLIENT_MESSAGE_DATA
• MQTT_SERVER_MESSAGE
• MQTT_SERVER_MESSAGE_DATA
447
Policy-Based SLB Commands
The following Policy-Based SLB command is supported:
l POLICY::bwlist id
l POLICY::source_rule
448
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
POLICY::bwlist id
Description Returns the group ID associated with an IP address in a black/white list.
This command causes the ACOS device to look in the black/white list
that is bound to the same virtual port to which the aFleX policy is
bound.
POLICY::bwlist id <ip> <bwlist_name>
This command causes the ACOS device to look in the specified list.
NOTE: When using POLICY::bwlist without a file name, the virtual port
requires a Policy Template with Black-White List file.
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
449
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• LB_FAILED
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
POLICY::source_rule
Description This command specifies the source rule name in the policy template
which is to be used during the policy matching process. Each source
rule has its priority. Even though the aFleX script selects a source rule,
the priority of this rule is used to compare with the source rule selected
by the original policy template matching (without aFleX). The higher
priority rule is chosen.
Example Use the following example to set the source destination match rule to
policy source matching.
when HTTP_REQUEST {
if { [HTTP::header exists "PASS"] } {
log "Header is matched. Set EP source rule as \"source-1\""
POLICY::source_rule set source-1
}
}
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
• HTTP_RESPONSE_CONTINUE
450
RADIUS Message Load-balancing Commands
The following commands are supported for RADIUS message load-balancing:
l RADIUS::avp
l RADIUS::code
l RADIUS::id
l RADIUS::length
451
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
RADIUS::avp
Description This command returns attribute-value pairs (AVPs) from a RADIUS
message. Bind the virtual port that uses this aFleX command to UDP
port 1812. It supports both IPv4 and IPv6 AVPs.
Example Use the following example to return attribute-value pairs (AVPs) from a
RADIUS message.
To return the attribute numbers and their corresponding values for all
AVPs present in the RADIUS message and print their values to the
console, use the following example:
when CLIENT_DATA {
set avpList [RADIUS::avp]
foreach avpTuple $avpList {
log "Attribute: [lindex $avpTuple 0], Value: [lindex
$avpTuple 2]"
}
Output
452
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Output
Value for attribute 2: World
Valid Events
• CLIENT_DATA
• SERVER_DATA
RADIUS::code
Description This command returns the Code field of a RADIUS message.
Syntax RADIUS::code
Example Use the following example to log the code field of a RADIUS message.
when CLIENT_DATA {
log "RADIUS Code: [RADIUS::code]"
}
Valid Events
• CLIENT_DATA
• SERVER_DATA
453
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
RADIUS::id
Description This command returns the Identifier field of a RADIUS message.
Syntax RADIUS::id
Example Use the following example to log the Identifier field of a RADIUS
message.
when CLIENT_DATA {
log "RADIUS Identifier: [RADIUS::id]"
}
Valid Events
• CLIENT_DATA
• SERVER_DATA
RADIUS::length
Description This command returns the Length field of a RADIUS message.
Syntax RADIUS::length
Example Use the following example to log the Length field of a RADIUS message.
when CLIENT_DATA {
log "RADIUS Length: [RADIUS::length]"
}
Valid Events
• CLIENT_DATA
• SERVER_DATA
454
RAM Caching Commands
The following RAM caching commands are supported on HTTP traffic (original proxy)
and HTTP2 traffic (new proxy):
l CACHE::disable
l CACHE::enable
l CACHE::expire
l CACHE::hits
These commands are supported on HTTP traffic (the original proxy), but not
supported on HTTP2 traffic (the new proxy).
l CACHE::age
l CACHE::headers
455
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
CACHE::age
Description This command returns the age (in seconds) of a cached object. The age
is how long the object has been in the cache.
Syntax CACHE::age
Example Use the following example to return the age of a cached object in 60
seconds.
when CACHE_REQUEST {
if { [CACHE::age] > 60 } {
CACHE::expire
log "The cache content expires when age > 60 seconds"
}
}
Valid Events
• CACHE_REQUEST
• CACHE_RESPONSE
• HTTP_REQUEST
• HTTP_RESPONSE
CACHE::disable
Description This command disables the current HTTP request from being cached.
Syntax CACHE::disable
Example Use the following example to disable the current HTTP request from
being cached.
when HTTP_REQUEST {
switch -glob [HTTP::uri] {
"*.jpg" { CACHE::enable }
456
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
"*.png" { CACHE::enable }
"*.gif" { CACHE::enable }
"*.css" { CACHE::enable 86400 }
"*.js" { CACHE::enable 86400 }
default { CACHE::disable }
}
}
Valid Events
• CACHE_REQUEST
• CACHE_RESPONSE
• HTTP_REQUEST
• HTTP_RESPONSE
CACHE::enable
Description This command caches an object, with the possibility of specifying how
long to cache the object for.
The <age> option specifies how long the object should be cached for, in
seconds. If the <age> option is not used, then the default time is the age
in the RAM caching template.
Example Use the following example to enable the current HTTP request from
being cached.
when HTTP_REQUEST {
switch -glob [HTTP::uri] {
"*.jpg" { CACHE::enable }
"*.png" { CACHE::enable }
"*.gif" { CACHE::enable }
"*.css" { CACHE::enable 86400 }
"*.js" { CACHE::enable 86400 }
default { CACHE::disable }
}
}
Valid Events
457
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• CACHE_REQUEST
• CACHE_RESPONSE
• HTTP_REQUEST
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
CACHE::expire
Description This command removes an object from the cache. It must be revalidated
by the server to be cached again.
Syntax CACHE::expire
Valid Events
• CACHE_REQUEST
• CACHE_RESPONSE
• HTTP_REQUEST
• HTTP_RESPONSE
458
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
CACHE::headers
Description This command returns the HTTP headers of a cached object. The name
and value of header fields are returned in a Tcl list.
Syntax CACHE::headers
Example Use the following example to return the HTTP headers of a cached
object.
when CACHE_RESPONSE {
log "Cache Headers: [CACHE::headers]"
}
Valid Events
• CACHE_REQUEST
• CACHE_RESPONSE
• HTTP_REQUEST
• HTTP_RESPONSE
CACHE::hits
Description This command returns the number of hits in the cache for a cached
object.
Syntax CACHE::hits
Example The following example logs the number of cache hits for a specific
HTTP::uri:
when HTTP_REQUEST {
log "CACHE Hits: There are [CACHE::hits] hits for
[HTTP::uri]"
}
Valid Events
• CACHE_REQUEST
• CACHE_RESPONSE
• HTTP_REQUEST
459
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• HTTP_RESPONSE
460
Resolve Commands
The following DNS resolution command is supported:
RESOLVE::lookup
For information about aFleX commands, see aFleX Commands.
461
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
RESOLVE::lookup
Description This command sends a DNS request to the DNS server for the list of IP
addresses associated with the specified domain name. This command
works when the DNS server is in asynchronous mode.
This command performs a DNS lookup for the specified domain name,
using the default DNS server.
NOTE: Using the following CLI command, configure a primary DNS server: ip
dns primary ip_address. A secondary DNS server can be configured
using the following CLI command: ip dns secondary ip_address.
This command will use the default DNS server. In case the default DNS
server fails, if a secondary DNS server is configured, the command
RESOLVE::lookup will use the secondary DNS server.
This command performs a DNS lookup for the specified domain name,
using the specified DNS server.
NOTE: For HTTP or HTTPS virtual ports, the valid events are HTTP_REQUEST
and HTTP_REQUEST_DATA. For TCP-proxy, the valid events are CLIENT_
ACCEPTED and CLIENT_DATA.
Use the following example to perform a DNS lookup with the default
DNS server:
when HTTP_REQUEST {
log "RESOLVE Lookup: [HTTP::host] resolves to
[RESOLVE::lookup [HTTP::host]]"
}
462
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Use the following example to perform a DNS lookup with the specified
DNS server:
when HTTP_REQUEST {
log "RESOLVE Lookup: [HTTP::host] resolves to
[RESOLVE::lookup @[Link] [HTTP::host]]"
}
Use the following example to dynamically choose the DNS server for the
DNS lookup, and then perform the DNS lookup:
when HTTP_REQUEST {
set cnt 0
set s1 [Link]
set s2 [Link]
set client_ip [IP::client_addr]
set method [HTTP::method]
set uri [HTTP::uri]
log "client ip = $client_ip"
if {[expr $cnt % 2]} {
set server "$s1"
} else {
set server "$s2"
}
set ips [RESOLVE::lookup @$server "[Link]"]
log "cnt = $cnt server = '$server' ips = '$ips'"
log "HTTP method = '$method' uri = '$uri'"
incr $cnt 1
}
when HTTP_RESPONSE {
log "Response: HTTP method = '$method' uri = '$uri'"
}
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• CLIENT_ACCEPTED
• CLIENT_DATA
463
SIP Commands
The following SIP commands are supported:
l SIP::call_id
l SIP::from
l SIP::header
l SIP::method
l SIP::respond
l SIP::response
l SIP::to
l SIP::uri
l SIP::via
For examples of the SIP command in use, see SIP Command Examples.
For information about aFleX commands, see aFleX Commands.
For information about SIP events, see SIP Events.
464
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
SIP::call_id
Description This command returns the value of the Call-ID header in a SIP request.
Syntax SIP::call_id
Valid Events
• SIP_REQUEST
• SIP_REQUEST_SEND
• SIP_RESPONSE
SIP::from
Description This command returns the value of the “From” header in a SIP request.
Syntax SIP::from
Valid Events
• SIP_REQUEST
• SIP_REQUEST_SEND
• SIP_RESPONSE
465
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• CLIENT_CLOSED
• CLIENT_DATA
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
SIP::header
Description This command either returns the specified SIP header, or else it inserts
a header name and a corresponding header value into the SIP header.
The <value> option specifies the header value. The <index> option
specifies which header level the value applies to in case of multiple
header levels. If an index is not specified, then aFleX applies the value
to the first header corresponding to the header-name.
SIP::header insert <header-name> <header-value> [<index>]
The <index> option specifies where to insert the new header. If the
optional index does not exist, then a “via” header is inserted at the
beginning of the SIP headers, and all other headers are inserted at the
end of the SIP headers. If the index is not specified, then the header is
inserted before other headers with the same name and value.
SIP::header remove <header-name> [index]
Valid Events
• SIP_REQUEST
• SIP_REQUEST_SEND
• SIP_RESPONSE
466
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• CLIENT_CLOSED
• CLIENT_DATA
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
SIP::method
Description This command returns what type the SIP request method is.
Syntax SIP::method
Valid Events
• SIP_REQUEST
• SIP_REQUEST_SEND
• SIP_RESPONSE
SIP::respond
Description This commands returns a response with the defined code, phrase, and
header name and corresponding header value.
Valid Events
467
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• SIP_REQUEST
• SIP_REQUEST_SEND
• SIP_RESPONSE
SIP::response
Description This command returns the SIP response code or phrase. You can also
use this command to rewrite the response code or phrase.
Valid Events
• SIP_REQUEST
• SIP_REQUEST_SEND
• SIP_RESPONSE
468
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• CLIENT_DATA
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
SIP::to
Description This command returns the value of the “To” header in the SIP request.
Syntax SIP::to
Valid Events
• SIP_REQUEST
• SIP_REQUEST_SEND
• SIP_RESPONSE
SIP::uri
Description This command returns the request’s URI.
Syntax SIP::uri
Valid Events
• SIP_REQUEST
469
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• SIP_REQUEST_SEND
• SIP_RESPONSE
SIP::via
Description This command returns the “via” information for SIP.
The above command returns the information in the SIP “via” header. If
the <index> option is specified, then only the information at that index
is returned.
SIP::via proto [<index>]
The above command returns the SIP “via” protocol part. If the <index>
option is specified, then only the information at the index is returned.
SIP::via sent_by [<index>]
The above command returns the “sent by” from the SIP “via”
information. If the <index> option is specified, then only the
information at the index is returned.
SIP::via received [<index>]
The above command returns the “received” value of the SIP “via”
information. If the <index> option is specified, then only the
information at the index is returned.
SIP::via branch [<index>]
470
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
The above command returns the “branch” value of the SIP “via”
information. If the <index> option is specified, then only the
information at the index is returned.
SIP::via maddr [<index>]
The above command returns the multicast address value of the SIP
“via” information. If the <index> option is specified, then only the
information at the index is returned.
SIP::via ttl [<index>]
The above command returns the TTL value of the SIP “via” information.
If the <index> option is specified, then only the information at the
index is returned.
Valid Events
• SIP_REQUEST
• SIP_REQUEST_SEND
• SIP_RESPONSE
471
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example 1
Use the following example to log all the available header values when a full SIP
request is received from the client and the SIP request method is subscribe.
when SIP_REQUEST {
if { [SIP::method] contains "SUBSCRIBE" } {
log "***************** SIP-REQUEST *******************"
log "SIP::call_id is [SIP::call_id]"
log "---------------------------------------------------"
log "SIP::from is [SIP::from]"
log "---------------------------------------------------"
log "SIP::header Via [SIP::header Via]"
log "SIP::header Via value index0 [SIP::header value Via 0]"
log "SIP::header Via index9 [SIP::header Via 9]"
log "SIP::header From [SIP::header From]"
log "SIP::header value From index0 [SIP::header value From 0]"
log "SIP::header From index9 <not exist> [SIP::header From 9]"
log "SIP::header To [SIP::header To]"
log "SIP::header To index0 [SIP::header To 0]"
log "SIP::header value To index9 <not exist> [SIP::header value To 9]"
log "SIP::header Call-ID [SIP::header Call-ID]"
log "SIP::header value Call-ID index0 [SIP::header value Call-ID 0]"
log "SIP::header value Call-ID index9 <not exist> [SIP::header value
Call-ID 9]"
log "SIP::header CSeq [SIP::header CSeq]"
log "SIP::header CSeq value index0 [SIP::header value CSeq 0]"
log "SIP::header CSeq index9 <not exist> [SIP::header CSeq 9]"
log "SIP::header Contact [SIP::header Contact]"
log "SIP::header value Contact index0 [SIP::header value Contact 0]"
log "SIP::header Contact index9 <not exist> [SIP::header Contact 9]"
log "SIP::header Max-Forwards [SIP::header Max-Forwards]"
log "SIP::header Event [SIP::header Event]"
log "SIP::header User-Agent [SIP::header User-Agent]"
log "SIP::header Expires [SIP::header Expires]"
log "SIP::header Allow [SIP::header Allow]"
log "SIP::header Accept [SIP::header Accept]"
log "SIP::header Content-length [SIP::header Content-length]"
log "SIP::header abc <not valid header> [SIP::header abc]"
log "---------------------------------------------------"
SIP::header remove Via
472
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
473
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example 2
Use the following example to look for SIP response codes, rewrite the codes to
customized messages, and log them when a full SIP response is received from the
server.
when SIP_RESPONSE {
if { [SIP::response code] equals "401" } {
SIP::response rewrite 411 Phrase_Unauthorized
log "SIP::response code [SIP::response code]"
log "SIP::response phrase [SIP::response phrase]"
}
if { [SIP::response code] equals "501" } {
SIP::response rewrite 511 Phrase_Not_Implemented
log "SIP::response code [SIP::response code]"
474
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example 3
Use the following example to log all the available header values when a full SIP
request is received from the client and the SIP request method is subscribe.
when SIP_REQUEST_SEND {
if { [SIP::method] contains "SUBSCRIBE" } {
log "***************** SIP-REQUEST-SEND *******************"
log "SIP::header Via 1 (request_sent) [SIP::header Via 1]"
475
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
log "---------------------------------------------------"
SIP::header insert From "<sip:218@[Link]>;tag=1043119751"
log "SIP::header insert From index1 [SIP::header From]"
476
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
477
SMTP Commands
The following category commands is supported:
l SMTP::mail
l SMTP::greet
l SMTP::ehlo
478
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
SMTP::mail
Description Retrieves MAIL command parameter (reverse-path).
Example Use the following example to retrieve the MAIL command parameter.
When SMTP_MAIL {
If {[SMTP::mail] equals [Link]} {
node [Link] 25
} else {
Node [Link] 25
}
}
Valid Events
SMTP::greet
Description Set EHLO ok messages.
Valid Events
479
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
SMTP::ehlo
Description Retrieve client's ehlo/helo message.
Syntax SMTP::ehlo
Example Use the following example to retrieve the client's ehlo message.
When SMTP_EHLO {
SMTP::ehlo
}
Valid Events
480
SSL Commands
The following SSL commands are supported:
l SSL::authenticate
l SSLI::bypass
l SSLI::cache_cert
l SSL::cert
l SSL::cipher
l SSL::collect
l SSL::disable
l SSLI::drop
l SSL::enable
l SSL::extensions
l SSL::hostname
l SSLI::inspect
l SSL::mode
l SSL::payload
l SSL::release
l SSL::renegotiate
l SSL::respond
l SSL::session invalidate
l SSL::sessionid
l SSL::template
l SSL::verify_result
481
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
SSL::authenticate
Description Use the following command to permanently, or for a single occurrence,
authenticate client SSL certificates. To set the depth to which the
authenticity of the certificate is inspected, use the keyword depth
followed by a number.
Example Use the following example to set the index and renegotiate variables
when a client establishes a connection with the ACOS device. After the
initial ssl handshake, the client authentication parameters will be
changed using the SSL::authenticate command. SSL::authenticate
will require the client to be authenticated once. SSL::authenticate
depth 6 will verify the client certificate until depth 6. After this, when
we renegotiate, if the certificate used for client authentication has
depth more than 6, the handshake should fail. If the SSL handshake is
successful the "SSL authenticate invalid CLIENTSSL_DATA: FAIL"
message would be printed in the logs.
when CLIENT_ACCEPTED {
set do_reneg 1
set index 1
}
when CLIENTSSL_HANDSHAKE {
SSL::collect
if {$do_reneg} {
log "Normal handshake for SSL authenticate invalid
CLIENTSSL_DATA"
log "Index for SSL authenticate invalid CLIENTSSL_DATA:
$index"
incr index
set do_reneg 0
} else {
log "SSL authenticate is invalid CLIENTSSL_DATA: FAIL"
log "Index for SSL authenticate invalid CLIENTSSL_DATA:
$index"
incr index
}
482
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
}
when CLIENTSSL_DATA {
log "Start SSL authenticate invalid CLIENTSSL_DATA"
SSL::authenticate once
SSL::authenticate depth 6
SSL::cert mode require
SSL::renegotiate
SSL::release
}
Valid Events
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_CLIENTHELLO
• CLIENTSSL_DATA
• CLIENTSSL_HANDSHAKE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
SSL::cert
Description Use the following command to view information on SSL certificates.
Use this command to return the SSL certificate with the specified level
in the certificate chain. Level 0 is the first level. This command will
provide certificate information in DER format. In release 2.6.1-P2 or
earlier, this command will provide certificate information in text format.
483
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Use this command to return the issuer of the certificate with the
specified level.
SSL::cert mode [request | require | ignore | auto]
Use this command to set the certificate mode. This setting will override
the mode that is set in template.
Example Use the following example to log the client certificate at level 0.
X509::text is used to convert the binary into ASCII for verification.
when CLIENTSSL_HANDSHAKE {
log "SSL cert for CLIENTSSL_HANDSHAKE is [X509::text
[SSL::cert 0]]"
}
Valid Events
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_CLIENTHELLO
• CLIENTSSL_HANDSHAKE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
SSL::cipher
Description Use the following command to return information on SSL ciphers.
484
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use the following example to log the cipher name, cipher bits, and
cipher version used in the SSL handshake.
when CLIENTSSL_HANDSHAKE {
log "SSL cipher_name is [SSL::cipher name]"
log "SSL cipher_bit is [SSL::cipher bits]"
log "SSL cipher_version is [SSL::cipher version]"
}
Valid Events
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
SSL::collect
Description Use the following command to collect SSL application data.
485
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Syntax SSL::collect
Example Use the following example to collect the SSL application information
when the client SSL handshake completes.
when CLIENTSSL_HANDSHAKE {
SSL::collect
}
Valid Events
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_CLIENTHELLO
• CLIENTSSL_HANDSHAKE
• SERVERSSL_CLIENTHELLO_SEND
• SERVERSSL_HANDSHAKE
• SERVERSSL_SERVERHELLO
SSL::disable
Description Use the following command to turn off server or client SSL.
NOTE: This command is only supported on the HTTP and the HTTPS. Other
types are not supported.
Example Use the following example to disable SSL and server-side SSL.
when CLIENT_ACCEPTED {
SSL::disable
SSL::disable serverside
}
Valid Events
• CLIENT_ACCEPTED
• CLIENTSSL_CLIENTHELLO
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_DATA
486
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• CLIENTSSL_HANDSHAKE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
SSL::enable
Description Use the following command to turn on client or server SSL.
NOTE: This command is only supported on the HTTP and the HTTPS. Other
types are not supported.
Example Use the following example to enable SSL and server-side SSL.
when CLIENT_ACCEPTED {
SSL::enable
SSL::enable serverside
}
Valid Events
• CLIENT_ACCEPTED
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_CLIENTHELLO
• CLIENTSSL_DATA
• CLIENTSSL_HANDSHAKE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
SSL::extensions
Description Use the following command to parse the SSL certificate extensions.
487
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Returns the byte array for the specified SSL certificate extension.
SSL::extensions -type <extension_type>
Returns the byte array for the specified SSL certificate extension type,
or an empty string if not found. Returns only the first instance if the
same extension type is present more than once.
SSL::extensions exists -type <extension_type>
Valid Events
• CLIENTSSL_CLIENTHELLO
• SERVERSSL_SERVERHELLO
• SERVERSSL_CLIENTHELLO_SEND
SSL::hostname
Description Gets the host name from the header of the CLIENT_HELLO message. If
the host name does not exist, it returns as NULL value.
The payload refers to the byte array collected from the TCP stream that
contains the CLIENT_HELLO message. It is used to extract data and
return the hostname.
When payload is passed to SSL::hostname, the byte array of the
CLIENT_HELLO message is provided to the command. The SSL::hostname
command then parses this data to extract the hostname.
Example The following example extracts and logs the SSL hostname from
incoming TCP packets:
when CLIENT_ACCEPTED {
TCP::collect
}
488
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
when CLIENT_DATA {
Log “[SSL::hostname]”
}
Example The following example calculates CLIENT_HELLO length based on the SSL
header. It collects data until the payload length exceeds the calculated
CLIENT_HELLO length. Once the required amount of data is collected, it
passes the collected TCP payload to SSL::hostname. This is particularly
useful when the CLIENT_HELLO message is fragmented across multiple
TCP packets.
when CLIENT_ACCEPTED {
TCP::collect
set packet_count 0
}
when CLIENT_DATA {
log "packet count $packet_count"
set offset 6
set payload [TCP::payload]
binary scan $payload @${offset}H6 length_hex
set length [format %d 0x$length_hex]
log "Rcv'd len [TCP::payload length]"
log $length
if {[TCP::payload length] < $length} {
incr packet_count
} else {
log "CLient data ssl hostname is [SSL::hostname
$payload]" <--- can also use [SSL::hostname [TCP::payload]]
TCP::release
}
}
Valid Events
• CLIENTSSL_CLIENTHELLO
• CLIENTSSL_HANDSHAKE
• CLIENT_DATA
489
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
SSL::mode
Description Use the following command on the server or the client to discover
whether SSL has been enabled or disabled. This command will return 1,
if SSL is turned on, or 2, if SSL is turned off.
Syntax SSL::mode
NOTE: When the certificate mode is set with this command, it will override the
mode set in the SSL template.
Example Use the following example SSL::mode command to ignore the example-
client-ssl-template mode.
when CLIENT_ACCEPTED {
SSL::template example-client-ssl-template
}
when HTTP_REQUEST {
log "The SSL mode is [SSL::mode]."
}
Valid Events
• CLIENT_ACCEPTED
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• SERVER_CONNECTED
• SERVERSSL_HANDSHAKE
SSL::payload
Description Use this command to return SSL data that has been collected, or to
replace the collected payload with the information that is provided.
490
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
NOTE: This command supports old SSL (N5) and new SSL (QAT, new N5, and
Software TLS1.3).
Use this command to return the SSL content that has been collected.
SSL::payload <offset> <size>
Use this command to return the accumulated SSL content starting from
<offset>.
SSL::payload <length>
Use this command to return the collected payload with the given data.
Example Use the following example to log the length of the SSL payload.
when CLIENTSSL_CLIENTCERT {
SSL::collect 100
log "Start collecting SSL data"
}
when CLIENTSSL_DATA {
log "SSL payload length is CLIENTSSL_CLIENTCERT:
[SSL::payload length]"
}
Example Use the following example to capture the original SSL payload. Replace
the GET response of the request with data to get new payload. Replace
the 0 to 50 bytes of SSL payload with the new payload.
when CLIENTSSL_CLIENTCERT {
SSL::collect 100
log "Start collecting SSL data"
}
when CLIENTSSL_DATA {
set data [SSL::payload]
set len [SSL::payload length]
log "SSL payload length before replace = $len"
log "SSL payload data before replace = $data"
491
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use the following example to log the SSL payload until size 100 of the
total size.
when CLIENTSSL_CLIENTCERT {
SSL::collect 164
}
when CLIENTSSL_DATA {
log "SSL payload of size CLIENTSSL_CLIENTCERT is
[SSL::payload 100]"
}
Valid Events
• CLIENTSSL_DATA
• SERVERSSL_DATA
SSL::release
Description Use the following command to release the SSL collect mode. This will
stop SSL application information from being gathered.
Syntax SSL::release
Example Use the following example to release the data collected so that the
session can continue. If the release fails, then the session fails.
when CLIENTSSL_HANDSHAKE {
SSL::collect 120
}
when CLIENTSSL_CLIENTCERT {
SSL::collect 100
log "Start collecting SSL data"
}
when CLIENTSSL_DATA {
492
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
• CLIENTSSL_DATA
• SERVERSSL_DATA
SSL::renegotiate
Description Only supported on devices with SSL Hardware. Use the following
command on the client after the SSL handshake has been completed to
mandate SSL renegotiation. Specify the disable keyword to prevent
client-side SSL renegotiation.
NOTE: This command is not compatible with TLS 1.3, as the SSL renegotiation
feature has been entirely removed from the TLS 1.3 protocol. As a
result, this command has no effect when TLS 1.3 is in use.
Example Use the following example to set the index and renegotiate variables
when a client establishes a connection with the ACOS device. After the
initial ssl handshake, the client authentication parameters will be
changed using the SSL::authenticate command. SSL::authenticate once will
require the client to be authenticated once. SSL::authenticate depth 6 will
verify the client certificate until depth 6. After this, when we
renegotiate, if the certificate used for client authentication has depth
more than 6, the handshake should fail. If the SSL handshake is
successful the "SSL authenticate invalid CLIENTSSL_DATA: FAIL"
message would be printed in the logs.
when CLIENT_ACCEPTED {
set do_reneg 1
set index 1
}
when CLIENTSSL_HANDSHAKE {
SSL::collect
493
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
if {$do_reneg} {
log "Normal handshake for SSL authenticate invalid
CLIENTSSL_DATA"
log "Index for SSL authenticate invalid CLIENTSSL_DATA:
$index"
incr index
set do_reneg 0
} else {
log "SSL authenticate is invalid CLIENTSSL_DATA: FAIL"
log "Index for SSL authenticate invalid CLIENTSSL_DATA:
$index"
incr index
}
}
when CLIENTSSL_DATA {
log "Start SSL authenticate invalid CLIENTSSL_DATA"
SSL::authenticate once
SSL::authenticate depth 6
SSL::cert mode require
SSL::renegotiate
SSL::release
}
Valid Events
• CLIENTSSL_DATA
• CLIENTSSL_HANDSHAKE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
SSL::respond
Description This command is used to send specific SSL data to the client in a client-
side event, or to the server in a server-side event. This command is
supported on HTTP2 (new proxy).
494
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
NOTE:
l This command supports old SSL (N5) and new SSL (QAT, new N5, and
Software TLS1.3).
l This command is supported on HTTP2 (new proxy).
Example Use the following example to send your own response to the client
instead of the server response.
when SERVERSSL_HANDSHAKE {
SSL::collect 100
log "Start collecting SSL data"
}
when SERVERSSL_DATA {
set data [SSL::payload]
if {$data contains "invite"} {
SSL::respond "HTTP/1.1 200 OK\r\n\r\n Session
active.\r\n"
} else {
SSL::respond "HTTP/1.1 404 OK\r\n\r\n Session page not
found.\r\n"
}
log "Sent SSL respond"
}
Valid Events
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_CLIENTHELLO
• CLIENTSSL_DATA
• CLIENTSSL_HANDSHAKE
• SERVERSSL_CLIENTHELLO_SEND
• SERVERSSL_DATA
• SERVERSSL_HANDSHAKE
• SERVERSSL_SERVERHELLO
495
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
SSL::session invalidate
Description Use the following command to invalidate the current session.
Specifically, this command drops the current SSL session ID from the
session cache to prevent its reuse, thereby enforcing a full TLS
handshake.
Example Use the following example to serve a maintenance message and enforce
a full TLS handshake by invalidating the SSL session for requests
containing "/maint".
when HTTP_REQUEST {
if { [HTTP::uri] contains "/maint" } {
HTTP::respond 200 content "<b>Under Maintenance</b>"
Connection Close
event HTTP_REQUEST disable
SSL::session invalidate
}
}
Valid Events
• CLIENT_ACCEPTED
• CLIENTSSL_DATA
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_CLIENTHELLO
• CLIENTSSL_HANDSHAKE
• SERVER_CONNECTED
496
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• SERVERSSL_HANDSHAKE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• SERVERSSL_DATA
• SERVERSSL_CLIENTHELLO_SEND
• SERVERSSL_SERVERHELLO
• SERVERSSL_SERVERCERT
SSL::session
Description This command retrieves session-related information for an ongoing SSL
connection.
Syntax SSL::session
Example Use the following example to log the current SSL session details when
an HTTP request is received over an SSL connection:
when HTTP_REQUEST {
log "SSL session information: [SSL::session]"
}
Valid Events
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
497
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
SSL::sessionid
Description Returns the current SSL session ID for the client side only, not for the
server side.
Syntax SSL::sessionid
Example Use the following example to log the SSL session id generated during
the SSL handshake.
when HTTP_REQUEST {
log "SSL session id for current session is
[SSL::sessionid]"
}
Valid Events
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
SSL::sessionsecret
Description Use the following command to return the SSL session key information
during the SSL/TLS handshake when a client is establishing a connection
with the server.
Syntax SSL::sessionsecret
Example Use the following example to log the SSL session secret for the current
SSL/TLS session.
498
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
when CLIENTSSL_HANDSHAKE {
log "SSL session secrets for current session is
[SSL::sessionsecret]"
}
The SSL session secrets are logged in the HEX string format: <label>
<client random> <secret>.
Valid Events
• CLIENTSSL_HANDSHAKE
• SERVERSSL_HANDSHAKE
SSL::template
Description Use the following command on the client or the server connection to
apply an SSL template.
Based on a client or server side, this command will apply the specified
SSL template.
SSL::template [clientside|serverside] <name>
NOTE: This command is only supported on the HTTP and the HTTPS. Other
types are not supported.
Example Use the following example to apply templates when a client establishes
a connection.
when CLIENT_ACCEPTED {
SSL::template example-client-ssl-template
SSL::template serverside example-server-ssl-template
}
Valid Events
499
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
SSL::verify_result
Description Use the following command to either set the <result_code> for the
peer certification verification or retrieve the result code of the peer
certification verification.
Example Use the following example to log the SSL handshake status code and
the error string related to the code.
when CLIENTSSL_HANDSHAKE {
log "SSL verify_result CLIENTSSL_HANDSHAKE:status
code [SSL::verify_result] in the logs"
log "SSL::verify result [X509::verify_cert_error_
string [SSL::verify_result]]"
}
Valid Events
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
• HTTP_REQUEST
500
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
SSLI::bypass
Description Use the following command to bypass SSL inspection.
NOTE: This command supports old SSL (N5) and new SSL (QAT, new N5, and
Software TLS1.3).
Syntax SSLI::bypass
Valid Events
• SERVERSSL_SERVERCERT
SSLI::cache_cert
Description This command is used to disable or enable caching of server certificate.
NOTE: This command supports old SSL (N5) and new SSL (QAT, new N5, and
Software TLS1.3).
501
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
when SERVERSSL_SERVERCERT {
if { [SSL::cert issuer 1] contains "Digi" } {
log "SERVERSSL_SERVERCERT: SSLI::cache_cert disable"
SSLI::cache_cert disable
}
}
Valid Events
• SERVERSSL_SERVERCERT
SSLI::drop
Description Use the following command to drop the SSL connection.
NOTE: This command supports old SSL (N5) and new SSL (QAT, new N5, and
Software TLS1.3).
Syntax SSLI::drop
Valid Events
• SERVERSSL_SERVERCERT
SSLI::inspect
Description Use the following command to enable SSL inspection for the flow.
NOTE: This command supports old SSL (N5) and new SSL (QAT, new N5, and
Software TLS1.3).
502
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Syntax SSLI::inspect
Inspects the flow and uses the alt key for signing.
Example Use the following example to inspect the flow and use the alt key for
signing:
when SERVERSSL_SERVERCERT {
if { [SSL::cert issuer 1] contains "[Link]" } {
log "SERVERSSL_SERVERCERT: inspect SSL"
SSLI::inspect use_alt_key
}
}
Valid Events
• SERVERSSL_SERVERCERT
503
Statistics Commands
The following commands related to statistics are supported:
l STATS::clear
l STATS::get
504
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
STATS::clear
Description Clears statistics for a real server (node), virtual server, or service group
(pool).
Valid Events
All
505
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
STATS::get
Description Retrieves statistics for a real server (node), virtual server, or service
group (pool).
The shared partition option applies the command to real servers in the
shared partition. By default, the STATS::get command acts only upon
the real servers located in the Role-Based Administration (RBA)
partition that contains the aFleX policy.
STATS::get virtual-server <vip-name| vipaddr>
[<port-num> <service-type>]
current-connection | total-connection | request-pkt |
response-pkt
[partition shared]
506
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
You can specify the virtual server by its name or VIP address (<vip-
name> or <vipaddr>).
Optionally, you can specify an individual port by its port number (0-
65535) and service type (tcp, udp, http, https, and so on). By default,
statistics for all the ports of the virtual server are returned.
The other options are the same as those for real servers.
STATS::get pool <pool-name> [member <ipaddr> <port-num>]
current-connection | total-connection | request-pkt |
response-pkt
[partition shared]
The other options are the same as those for real servers and virtual
servers.
Example The following policy will select a real server based on the current
connection counter:
when CLIENT_ACCEPTED {
set total1 [STATS::get server [Link] current-
connection]
set total2 [STATS::get server [Link] current-
connection]
if { $total1 > $total2 } {
node [Link] 80
} else {
node [Link] 80
}
}
Valid Events
All
507
Table Commands
You can use the following aFleX commands to manage a table of data entries:
l table add
l table append
l table delete
l table incr
l table keys
l table lifetime
l table lookup
l table replace
l table set
l table timeout
508
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Default Values
If <timeout> is not specified, the timeout is set to the default of 180 seconds.
If <lifetime> is not specified, the lifetime is set to “indefinite”.
Depending on the aFleX event used in the policy, you can track connections or
requests. The CLIENT_CONNECTED event represents TCP connections, whereas the
HTTP_REQUEST event represents every individual request.
The <lifetime> option sets the entry to expire after the specified period of time,
regardless of how many changes or lookups are performed on the entry.
An entry can have both a configured lifetime and timeout. The entry is removed from
the table for whichever expiration time comes first.
509
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
table add
Description Adds or returns the value for a specified key in the table.
Adds a key to the table with the specified <key> number and associated
<value>. Optionally, you can apply a <timeout> and <lifetime> to the
entry.
NOTE: If the key already exists, a key is not inserted and the existing value is
not returned. When a new key is added, the existing value is returned.
Valid Events
All.
table append
Description Appends a string to the value associated with the specified key
If -notouch is specified, then any existing entries for the key will not
have an updated timestamp.
NOTE: If the key does not exist, then no action is taken. This command returns
the value of the entry after the operation is complete.
Valid Events
All.
510
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
table delete
Description Deletes elements of a table.
Valid Events
All.
table incr
Description Increments the value associated with a key.
Increments the value associated with the <key>, in the specified table. If
you do not specify a value for <num>, 1 is used by default. If -notouch is
specified, then any existing entries for the key will not have an updated
timestamp.
NOTE: This command returns the entry’s value after the operation is complete.
If the specified key does not exist, then no action is taken.
Valid Events
All.
511
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
table keys
Description Returns a list of key and value pairs in the specified table.
Returns list of keys and value pairs (without updated timestamp), and
number of keys in the specified table.
table keys <name> -notouch
NOTE: A10 Networks does not recommend using this command frequently in
an aFleX policy. The table keys command provides useful debugging
capabilities, but can lower system performance when used repeatedly.
Valid Events
All.
table lifetime
Description Returns the lifetime for the specified key. This command returns -1 if no
lifetime is set for the specified key or the lifetime is indefinite.
512
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
All.
table lookup
Description Returns the value associated with the specified key.
Returns the value associated with <key>. Any existing entries for the
key will not have an updated timestamp.
Valid Events
All.
table replace
Description Replaces the value in the table associated with the specified key or
value. If the specified key does not exist, no action is taken and an
empty string is returned.
Replaces the value in the table with the specified <key> or <value>.
Returns new value after replacement.
table replace <name> <key> <value> <timeout> <lifetime>
513
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Replaces the value with the specified <key> or <value> and applies a
<timeout> and <lifetime> to the entry. Returns new value after
replacement.
Valid Events
All.
table set
Description Sets a value in the table for an existing key. Adds a table and a key if
one does not already exist.
Sets the <value> of <key> and returns the entry’s value. Also applies a
<timeout> and <lifetime> to the entry.
Valid Events
All.
table timeout
Description Sets or returns the timeout for a specific key in a table.
514
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
All.
Table Examples
The following aFleX script examples use table commands:
l Example 1 uses table commands to blacklist IP addresses that make large number
of DNS queries.
l Example 2 uses table commands to block IP addresses if there are large number of
failed login attempts.
l Example 3 shows an example of how to display and delete table commands.
Example 1
In this example, the aFleX script blacklists an IP addresses for 10 minutes (600
seconds) if traffic from the IP address makes more than 10 DNS queries per second. It
uses the lifetime for the $::HOLDTIME:
when RULE_INIT {
set ::MAXQUERY 10
set ::HOLDTIME 600
}
when DNS_REQUEST {
if { [table lookup "blacklist" [IP::client_addr]] != "" } {
log "The Blacklist for [IP::client_addr] expires in [table
lifetime "blacklist" -remaining [IP::client_addr]] seconds"
drop
return
515
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
}
if { [table lookup tmp_table [IP::client_addr]] == "" } {
table set tmp_table [IP::client_addr] 1 indef 1
log "The table entry created for [IP::client_addr]"
return
}
set count [table incr tmp_table [IP::client_addr]]
log "The DNS Query $count of $::MAXQUERY for [IP::client_addr]"
if { $count > $::MAXQUERY } {
table add "blacklist" $key "blocked" indef $::HOLDTIME
log "The Blacklist entry created for [IP::client_addr]"
table delete tmp_table $key
drop
return
}
}
Example 2
In this example, the aFleX script blocks an IP address for 10 minutes (600 seconds) if
there are 3 failed login attempts. It uses the timeout for the $::HOLDTIME:
when RULE_INIT {
set ::MAXTRIES 3
set ::HOLDTIME 600
set ::LOCATION "/[Link]?p=failed"
}
when HTTP_REQUEST {
if { [table lookup "failedlogins" -notouch [IP::client_addr]] ==
$::MAXTRIES } {
HTTP::respond 200 content "You have been blocked, you can try
again in [table timeout "failedlogins" -remaining [IP::client_addr]]
seconds"
log "Login is blocked for [IP::client_addr] expires in [table
timeout "failedlogins" -remaining [IP::client_addr]] seconds"
}
}
when HTTP_RESPONSE {
if { [HTTP::header exists "Location"] } {
if { ([HTTP::header "Location"] ends_with $::LOCATION) } {
516
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example 3
In this example, the aFleX script presents all the entries in the table and gives the
option to delete a table. Show table contents with: [Link]
Delete table contents with: [Link]
when HTTP_REQUEST {
set ACTION [getfield [HTTP::uri] ":" 1]
set TABLE [getfield [HTTP::uri] ":" 2]
if { $ACTION eq "/flush" } {
table delete $TABLE -all
HTTP::respond 200 content "Table $TABLE deleted... <a
href=\"/status:$TABLE\">Back to STATUS</a>" Content-Type "text/html"
} elseif { $ACTION eq "/status" } {
set response "<html><head><title>Contents of Table:
$TABLE</title></head>"
append response "<body><center><h1>Contents of Table:
$TABLE</h1><table border=\"1\" cellpadding=\"5\" cellspacing=\"0\">"
append response "<tr><th>Key</th><th>Value</th></tr>"
set i 0
foreach tr [table keys $TABLE] {
incr i
if { $i == 1 } {
append response "<tr><td>$tr</td>"
}
if { $i == 2 } {
append response "<td>$tr</td></tr>"
set i 0
517
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
}
}
append response "</table><p>DELETE TABLE: <a
href=\"/flush:$TABLE\">$TABLE</a></p>"
append response "</center></body></html>"
HTTP::respond 200 content $response Content-Type "text/html"
} else {
HTTP::respond 200 content "Usage is prohibited!"
}
}
518
TCP Commands
The following TCP commands are supported:
l TCP::client_port
l TCP::close
l TCP::collect
l TCP::local_port
l TCP::mss
l TCP::notify
l TCP::offset
l TCP::option
l TCP::payload
l TCP::release
l TCP::remote_port
l TCP::respond
l TCP::rtt
l TCP::server_port
519
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
TCP::client_port
Description This command will return the TCP port/service number of the specified
client. It is equivalent to the command clientside { TCP::remote_
port } and client_port.
Syntax TCP::client_port
Example Use the following example to log the TCP port/service number of the
specified client.
when CLIENT_ACCEPTED {
log "Connection has been achieved here: [IP::client_addr]:
[TCP::client_port]"
}
Valid Events
• AAM_AUTHENTICATION_INIT
• AAM_AUTHORIZATION_CHECK
• AAM_AUTHORIZATION_INIT
• AAM_RELAY_INIT
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_CLIENTHELLO
• CLIENTSSL_DATA
• CLIENTSSL_HANDSHAKE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• LB_FAILED
• LB_SELECTED
• SERVERSSL_CLIENTHELLO_SEND
520
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• SERVERSSL_DATA
• SERVERSSL_HANDSHAKE
• SERVERSSL_SERVERCERT
• SERVERSSL_SERVERHELLO
• SIP_REQUEST
• SIP_REQUEST_SEND
• SIP_RESPONSE
TCP::close
Description This command will close the TCP connection.
NOTE: This command supports old SSL (N5) and new SSL (QAT, new N5, and
Software TLS1.3).
Syntax TCP::close
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
521
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• HTTP_RESPONSE_DATA
• LB_FAILED
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
TCP::collect
Description This command will cause TCP to start gathering the specified amount of
content data.
For information about using this command with generic TCP Proxy, see
Support for Generic TCP Proxy.
Valid Events
• CLIENT_ACCEPTED
• CLIENT_DATA
• SERVER_CONNECTED
• SERVER_DATA
522
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example
when CLIENT_ACCEPTED {
TCP::collect 1024
}
when CLIENT_DATA {
log "Here is the length of the payload: [TCP::payload
length]"
if { [TCP::payload 15] contains "internal" } {
pool service_group_internal
} else {
pool example_service_group
}
}
TCP::collect
523
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example
when CLIENT_ACCEPTED {
TCP::collect
}
when CLIENT_DATA {
log "Here is the length of the payload: [TCP::payload
length]"
if { [TCP::payload 15] contains "internal" } {
pool service_group_internal
} else {
pool example_service_group
}
TCP::release
TCP::collect
}
524
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
525
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use the following example to set and log the TCP payload length. Check
if the payload contains a certain string and use the appropriate service
group for the content. Alternatively, use a different service group and
release it. This example shows the gathering of the first 1000 bytes of
data and triggering a DATA event using the following key commands:
• TCP::collect command using <length> option in CLIENT_
ACCEPTED event
• TCP::release command placed at the end of CLIENT_DATA event
when CLIENT_ACCEPTED {
TCP::collect 1000
}
when CLIENT_DATA {
set tcplen [TCP::payload length]
log "Here is the length : ($tcplen)"
if { [TCP::payload ] contains "ABC" } {
pool abc_service_group
} else {
pool web_service_group
}
TCP::release
}
NOTE:
• Ensure the correct <length> value, otherwise if the
TCP payload total is less than that specified by collect
<length>, the ACOS device does not forward the data
to the server.
• aFleX does not allow another use of the
TCP::collect command in the DAT event when
collect <length> is defined.
Example This example shows the gathering of the first three data packets
followed by the action of forwarding the data to the server by using
these commands:
• TCP::collect command used in CLIENT_ACCEPTED event
526
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
when CLIENT_ACCEPTED {
TCP::collect
set packet_count 0
}
when CLIENT_DATA {
incr packet_count
if { $packet_count >= 3 } {
log "Here is the length of the payload: [TCP::payload
length]"
if { [TCP::payload] contains "internal" } {
pool service_group_internal
} else {
pool example_service_group
}
TCP::release
}
}
Valid Events
The following events are valid for this use of the TCP::collect
command:
• CLIENT_ACCEPTED
• CLIENT_DATA
• SERVER_CONNECTED
• SERVER_DATA
TCP::local_port
Description This command will return the local TCP port/service number.
Syntax TCP::local_port
527
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example This example shows a cookie modification using the local port
information. If the port is 80, the cookie has "HttpOnly" added to it. If
the port is 443, "HttpOnly" and "Secure" is added to the cookie.
when RULE_INIT {
set ::DEBUG 0
}
when HTTP_REQUEST {
set PORT [TCP::local_port]
}
when HTTP_RESPONSE {
set current_time [TIME::clock seconds]
foreach cookie_name [HTTP::cookie names] {
if { [HTTP::cookie exists "$cookie_name"] } {
set new_cookie "$cookie_name=[HTTP::cookie value
"$cookie_name"]"
if { [HTTP::cookie expires "$cookie_name"] > $current_
time } {
set cookie_expires [clock format [HTTP::cookie expires
"$cookie_name"] -format {%a, %d %b %Y %H:%M:%S GMT} -gmt 1]
append new_cookie "; Expires=$cookie_expires" }
if { [HTTP::cookie domain "$cookie_name"] ne "" } {
append new_cookie "; Domain=[HTTP::cookie domain "$cookie_
name"]" }
if { [HTTP::cookie path "$cookie_name"] ne "" } { append
new_cookie "; Path=[HTTP::cookie path "$cookie_name"]" }
if { $PORT == 443 } { append new_cookie "; Secure" }
if { $PORT == 80 or $PORT == 443 } { append new_cookie
"; HttpOnly" }
if { ($::DEBUG == 1) } { log "Set-Cookie $new_cookie" }
HTTP::cookie remove "$cookie_name"
HTTP::header insert Set-Cookie "$new_cookie"
}
}
}
Valid Events
• AAM_AUTHENTICATION_INIT
528
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• AAM_AUTHORIZATION_CHECK
• AAM_AUTHORIZATION_INIT
• AAM_RELAY_INIT
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_CLIENTHELLO
• CLIENTSSL_DATA
• CLIENTSSL_HANDSHAKE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• LB_FAILED
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
• SERVERSSL_CLIENTHELLO_SEND
• SERVERSSL_DATA
• SERVERSSL_HANDSHAKE
• SERVERSSL_SERVERCERT
• SERVERSSL_SERVERHELLO
• SIP_REQUEST
• SIP_REQUEST_SEND
• SIP_RESPONSE
529
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
TCP::mss
Description This command will return the maximum segment size (MSS) for a TCP
connection.
Syntax TCP::mss
Example Use the following example to log the MSS for a TCP connection.
when CLIENT_ACCEPTED {
log "Here is the maximum segment size: [TCP::mss]"
}
Valid Events
• AAM_AUTHENTICATION_INIT
• AAM_AUTHORIZATION_CHECK
• AAM_AUTHORIZATION_INIT
• AAM_RELAY_INIT
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_CLIENTHELLO
• CLIENTSSL_DATA
• CLIENTSSL_HANDSHAKE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• LB_FAILED
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
530
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• SERVER_DATA
• SERVERSSL_CLIENTHELLO_SEND
• SERVERSSL_DATA
• SERVERSSL_HANDSHAKE
• SERVERSSL_SERVERCERT
• SERVERSSL_SERVERHELLO
• SIP_REQUEST
• SIP_REQUEST_SEND
• SIP_RESPONSE
TCP::notify
Description This command will notify the system that the end of a message has
been reached, and that the message is ready for load balancing.
Example This example shows how to use notify for load balancing messages
through TCP.
when CLIENT_ACCEPTED {
TCP::collect
}
when CLIENT_DATA {
log "Here is the payload: [TCP::payload] "
TCP::release
TCP::notify eom
log "Here is the payload after release: [TCP::payload]"
TCP::collect
}
Valid Events
• CLIENT_DATA
• SERVER_DATA
531
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
TCP::offset
Description This command will return the position in the TCP data stream where
the collected TCP data began.
Syntax TCP::offset
Example Use the following example to return the position in the TCP data
stream.
when CLIENT_ACCEPTED {
TCP::collect
}
when CLIENT_DATA {
if { [TCP::offset] > 1000 } {
TCP::release
}
}
Valid Events
• CLIENT_DATA
• SERVER_DATA
TCP::option
Description This command will retrieve, set, or unset the raw value of the specified
option kind from the TCP header.
532
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
533
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
534
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
NOTE: For the following TCP option types, they cannot be set or unset: MSS,
SACK and Window Scale.
Example Use this example to get the value for different options set by client in
the TCP header.
when CLIENT_ACCEPTED {
log " TS = [TCP::option get 8]"
log " mss = [TCP::option get 2]"
log " wscale = [TCP::option get 3]"
log " SACK_permit = [TCP::option get 4]"
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
TCP::payload
Description This command will return the accumulated TCP data content, or replace
the gathered payload with the specified data.
535
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
This will return the accumulated TCP data content start from <offset>.
TCP::payload length
This will return the amount of accumulated TCP data content in bytes.
TCP::payload <offset> <size> <data>
This will return the gathered payload with the specified data.
TCP::payload replace <offset> <size> <data>
This will replace the gathered payload with the specified data.
NOTE: Use of the TCP::payload replace command is only supported for TCP-
proxy, TCP, and FTP virtual ports.
NOTE: After TCP data has been released with the use of the TCP::release
command, it is no longer part of the TCP data payload, so it will not be
returned with the TCP::payload command.
Example Use the following example to return the accumulated TCP data content.
when CLIENT_ACCEPTED {
TCP::collect
}
when CLIENT_DATA {
if { [TCP::payload] contains "internal" } {
pool service_group_internal
} else {
pool service_group_tcp
}
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
536
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
TCP::release
Description This command will cause TCP to resume processing the connection and
flush collected data.
Syntax TCP::release
Example Use the following example to resume processing the connection and
flush collected data.
when CLIENT_ACCEPTED {
TCP::collect
}
when CLIENT_DATA {
if { [TCP::offset] > 1000 } {
TCP::release
}
}
Example Use the following example to show message load balancing to help
determine the proper payload.
when CLIENT_ACCEPTED {
TCP::collect
}
537
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
when CLIENT_DATA {
log "Here is the payload: [TCP::payload] "
TCP::release 20
TCP::notify eom
log "Here is the payload after release: [TCP::payload]"
TCP::collect
}
Valid Events
• CLIENT_DATA
• SERVER_DATA
TCP::remote_port
Description This command will return the remote TCP port/service number. It
replaces the remote_port command.
Syntax TCP::remote_port
Example Use the following example to log the remote TCP port.
when SERVER_CONNECTED {
log "Here is the server remote TCP port: [TCP::remote_
port]"
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• SERVER_CLOSED
538
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• SERVER_CONNECTED
• SERVER_DATA
TCP::respond
Description This command will send the specified data directly to the peer. It can
also be used to complete a protocol handshake.
NOTE:
l This command supports only old SSL (N5) and does not support new
SSL (QAT, new N5, and Software TLS1.3).
l This command will not work if applied to an HTTP/HTTPS virtual port.
This command with the <data> parameter will specify the data to send
to the peer.
NOTE: This command will not work if applied to an HTTP virtual port.
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
539
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• CLIENT_DATA
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
TCP::rtt
Description This command will return the smoothed round-trip time (RTT) estimate
for a TCP connection.
Syntax TCP::rtt
• Get the actual round-trip time in milliseconds by dividing the
returned value by 2.
• The RTT will take some time to converge.
Example Use the following example to get the actual round-trip time in
milliseconds.
when HTTP_REQUEST {
set rtt [TCP::rtt]
}
when HTTP_RESPONSE {
if { $rtt < 1600 } {
log "Here is the round-trip time: $rtt for
[IP::client_addr] - without compress applied."
COMPRESS::disable
} else {
log "Here is the round-trip time: $rtt for
[IP::client_addr] - with compress applied."
COMPRESS::enable
COMPRESS::gzip level 3
}
}
Valid Events
• AAM_AUTHENTICATION_INIT
• AAM_AUTHORIZATION_CHECK
• AAM_AUTHORIZATION_INIT
540
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• AAM_RELAY_INIT
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_CLIENTHELLO
• CLIENTSSL_DATA
• CLIENTSSL_HANDSHAKE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• LB_FAILED
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
• SERVERSSL_CLIENTHELLO_SEND
• SERVERSSL_DATA
• SERVERSSL_HANDSHAKE
• SERVERSSL_SERVERCERT
• SERVERSSL_SERVERHELLO
• SIP_REQUEST
• SIP_REQUEST_SEND
• SIP_RESPONSE
541
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
TCP::server_port
Description This command will return the TCP port/service number of the specified
server. It is the same as using the serverside { TCP::remote_port }
command and the obsolete variable server_port.
Syntax TCP::server_port
Example Use the following example to log the TCP port of the specified server.
when SERVER_CONNECTED {
log "Here is the server port: [TCP::server_port]"
}
Valid Events
• AAM_RELAY_INIT
• CLIENT_CLOSED
• CLIENT_DATA
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
• LB_SELECTED
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
• SIP_REQUEST
• SIP_REQUEST_SEND
• SIP_RESPONSE
542
Template Commands
The Template commands enable you to access individual configuration parameters
on a per template basis. The commands listed below allow you to check for the
existence of certain template types on a virtual server. Further, you can use these
commands to access configuration parameters for a template.
The following template commands are supported:
l TEMPLATE::cache
l TEMPLATE::client_ssl
l TEMPLATE::conn_reuse
l TEMPLATE::exists
l TEMPLATE::http
l TEMPLATE::server_ssl
l TEMPLATE::tcp
l TEMPLATE::udp
543
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
TEMPLATE::cache
Description This command gets the value of the parameter for a RAM cache
template.
This command returns the value for the specified <setting> in the
designated RAM cache template. For the <setting> variable, you can
enter one of the following options:
• name
• accept_reload_req
• age
• default_policy_nocache
• disable_insert_age
• disable_insert_via
• max_cache_size
• max_content_size
• min_content_size
• policy
• remove_cookies
• replacement_policy
• verify_host
Example The following example logs the cache age value in the assigned
template.
when CACHE_REQUEST {
log "Cache age of URI [HTTP::uri] refreshed to
[TEMPLATE::cache age]"
}
Valid Events
All.
544
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
TEMPLATE::client_ssl
Description This command gets the value of the parameter for the client SSL
template.
This command returns the value for the specified <setting> in the
designated client SSL template. For the <setting> parameter, enter one
of the following options:
• name
• ca_cert
• cert
• chain_cert
• cipher
• client_certificate
• close_notify
• crl
• key
• session_cache_size
• ssl_false_start_disable
Example The following example checks if a client-side SSL template exists on the
virtual port, and if the SSL template is found, then a log is generated
containing the template name.
when CLIENT_ACCEPTED {
if { [TEMPLATE::exists client_ssl] == 1 } {
log "The TEMPLATE exists and says YES.”
log "The TEMPLATE Client SSL name is
[TEMPLATE::client_ssl name]."
} else {
log "No, the client SSL Template is not configured."
}
545
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
All.
TEMPLATE::conn_reuse
Description This command gets the value of the parameter for the connection reuse
template.
Example The following example checks if a connection reuse template exists and
if the current number of connections is greater than the limit per
server. If so, it forwards the traffic to a special service port.
when HTTP_REQUEST {
if { [TEMPLATE::exists conn_reuse] == 1 } {
set curr_conn [STATS::get server [Link] 80 tcp
current-connection]
if { $curr_conn > [TEMPLATE::conn_reuse limit-per-
server] } {
node [Link] 80
}
}
}
Valid Events
All.
546
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
TEMPLATE::exists
Description This command determines whether a template is bound to a virtual
server. The command returns a “1” integer value if a template is
configured on the virtual server, and it returns a “0” integer value if the
template is not configured on the virtual server.
Example The following example checks if a Client SSL template has been applied
to the virtual server. If yes, then the command will return a “1” value,
and this will trigger ACOS to create a log message indicating that the
client SSL template is enabled.
when CLIENT_ACCEPTED {
547
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
if { [TEMPLATE::exists client_ssl] == 1 } {
log "The client SSL template is configured."
}
}
Example The following example checks if a Server SSL template has been applied
to the virtual server. If yes, then the command will return a “1” value,
and this will trigger ACOS to create a log message indicating that the
server SSL template is enabled.
when SERVER_CONNECTED {
if { [TEMPLATE::exists server_ssl] == 1 } {
log "The server SSL template is configured."
}
}
Valid Events
All.
TEMPLATE::http
Description This command gets the value of the parameter for the HTTP template.
This command returns the value for the specified <setting> for the
designated HTTP template. For the <setting> parameter, enter one of
the options listed below:
• name
• compress_level
• compress_content_type_excludes
• compress_uri_excludes
• compress_enable
• compress_min_size
• compress_content_type
• failover_url
548
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• host_switching
• insert_client_ip
• log_retry
• redirect_rewrite
• request_header_erase
• request_header_insert
• response_header_erase
• response_header_insert
• retry_on_5xx
• retry_on_5xx_per_req
• strict_transaction_switch
• term_11client_hdr_client_close
• url_hash_persist
• url_switching
Example The following example checks if an HTTP template exists. If so, it skips
the compression for the URI that contains the string “example” when
the compression level is 1.
when HTTP_REQUEST {
if { [TEMPLATE::exists http] == 1 } {
#skip low level compression for certain uri
if { [HTTP::uri] contains "example" } {
if { [TEMPLATE::http comparess_level] == 1 } {
COMPRESS::disable
}
}
}
}
Valid Events
All.
549
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
TEMPLATE::server_ssl
Description This command gets the value of the parameter for the server SSL
template.
This command returns the value for the specified <setting> for the
designated Server SSL template. For the <setting> parameter, enter
one of the options listed below:
• name
• ca_cert
• cert
• cipher
• close_notify
• key
• version
Example The following example checks if a Server SSL template exists, then logs
all the listed settings, otherwise logs that it is not configured on the
virtual port.
when CLIENT_ACCEPTED {
if { [TEMPLATE::exists server_ssl] == 1 } {
log "*** Template server_ssl is configured on vport ***"
log "*** Name: [TEMPLATE::server_ssl name]***"
log "*** ca_cert: [TEMPLATE::server_ssl ca_cert]***"
log "*** cert: [TEMPLATE::server_ssl cert]***"
log "*** close_notify: [TEMPLATE::server_ssl close_
notify]***"
log "*** cipher: [TEMPLATE::server_ssl cipher]***"
log "*** version: [TEMPLATE::server_ssl version]***"
log "*** key: [TEMPLATE::server_ssl key]***"
} else {
log "template server_ssl is not configured on vport"
}
}
Valid Events
550
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
All.
TEMPLATE::tcp
Description This command gets the value of the parameter for the TCP template.
This command returns the value for the specified <setting> in the
designated TCP template. For the <setting> parameter, enter one of
the choices listed below:
• name
• force_delete_timeout
• half_close_idle_timeout
• idle_timeout
• initial_window_size
• reset_fwd
• reset_rev
Valid Events
All.
TEMPLATE::udp
Description This command gets the value of the parameter for the UDP template.
551
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
This command returns the value for the specified <setting> for the
designated UDP template. For the <setting> parameter, enter one of
the options below:
• name
• aging
• idle_timeout
• qos
• re_select_if_server_down
• stateless_conn_timeout
Valid Events
All.
552
Time Commands
The time commands are used to return and format the time.
The following time commands are supported:
l TIME::clock
553
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
TIME::clock
Description This command returns the system time in seconds or milliseconds.
Descriptor Returns
%% Inserts a “%.”
%a Weekday, abbreviated (Mon, Tues, Wed, etc.).
%A Weekday, unabbreviated (Monday, Tuesday, etc.).
%b Month, abbreviated (Jan, Feb, etc.).
%B Month, unabbreviated (January, February, etc.).
554
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Descriptor Returns
%c Locale specific date and time.
%C First two digits of the year (19, 20, etc).
%d Day of the month, with leading zero if necessary (01 -
31).
%D Date, in format “%m/%d/%y.”
%e Day of month, without leading zeros (1 - 31).
%g The ISO year (corresponding to the ISO week, “%V”),
expressed as a two-digit year-of-the-century, with
leading zero if necessary.
%G The ISO year corresponding to the ISO week (%V),
expressed as a four-digit number.
%h Month name, abbreviated (Jan, Feb, etc.).
%H Hour, 24-hour format, with leading zeros if necessary
(00-23).
%I Hour, 12-hour format, with leading zeros if necessary
(01-12).
%j Day of the year, with leading zeros if necessary (000-
366).
%k Hour, 24-hour format, no leading zeros (0-23).
%l Hour, 12-hour format, no leading zeros (1-12).
%m Month, as a number (01-12).
%M Minute (00-59).
%n Line break.
%p Displays AM or PM.
%r Time in a locale-specific "meridian" format. The
"meridian" format in the default "C" locale is
"%I:%M:%S %p".
%R Time in hours and minutes (same as “%H:%M).
%s Number of seconds since the TIME::clock command
was executed.
555
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Descriptor Returns
%S Seconds (00-59).
%t Tab.
%T Displays time in hours, minutes and seconds (same as
“%H:%M:%S”).
%u Weekday, as a number (Monday=1, Sunday=7).
%U Week of the year, with Sunday as first day of the week
(00-52).
%V Week of the year according to ISO rules (The week
including January 4 is week 1).
%w Weekday, as a number (Sunday=0, Saturday=6).
%W Week of the year, with Monday as first day of the
week (00-52).
%x Locale specific date format.
%X Locale specific 24-hour time format.
%y Last two digits of the year (00-99).
%Y Four-digit year (for example, 1985)
%Z Time zone.
Example Use this example to log the current system time when a TCP connection
is established:
when CLIENT_ACCEPTED {
set current_time [TIME::clock]
log "Current system time (epoch): $current_time"
}
Example Use this example to log the time a client connection is established,
formatted as a 4-digit year, month, day, and time (HH:MM:SS):
when CLIENT_ACCEPTED {
log "The client [IP::client_addr] connected at
[TIME::clock format [TIME::clock seconds] -format {%Y/%m/%d at
%H:%M:%S}]"
}
556
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
All.
557
UDP Commands
The following link commands are supported:
l UDP::client_port
l UDP::local_port
l UDP::payload
l UDP::remote_port
l UDP::respond
l UDP::server_port
558
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
UDP::client_port
Description This command returns the UDP port/service number for the designated
client. It is equivalent to the command clientside { UDP::remote_
port }.
Syntax UDP::client_port
Example Use the following example when a client has established a connection if
the client port is UDP 123, then use the service group for UDP.
when CLIENT_ACCEPTED {
if { [UDP::client_port] == 123 } {
pool service_group_udp
}
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
UDP::local_port
Description This command returns the local UDP port/service number.
Syntax UDP::local_port
Example Use the following example when a client has established a connection
to use service group for DNS if the local UDP port is 53. Otherwise, if
the local port is UDP 123, then use the service group for UDP. If
anything else, then drop.
when CLIENT_ACCEPTED {
if { [UDP::local_port] == 53 } {
559
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
pool service_group_dns
} elseif { [UDP::local_port] == 123 } {
pool service_group_udp
} else {
drop
}
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
UDP::payload
Description This command returns the content or length of the current UDP
payload.
This option returns the length, in bytes, of the current UDP payload.
UDP::payload <offset> <size>
This option returns the content of the current UDP payload from
<offset>.
UDP::payload replace <offset> <size> <new_data>
560
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use the following example to use dns_service_group1 when the UDP
payload index from 12 through 20 contains the example string, else use
dns_service_group2.
when CLIENT_DATA {
if { [UDP::payload 12 20] contains "example string" } {
pool dns_service_group1
} else {
pool dns_service_group2
}
}
Example In the following example, the payload is emptied and then re-filled with
the data from the “packetdata” string that is sent to the server.
when CLIENT_DATA {
UDP::payload replace 0 [UDP::payload length] ""
# craft a string to hold data, 0x01 0x00 0x00 0x00 0x02 0x00
0x00 0x00 0x03 0x00 0x00 0x00
set packetdata [binary format i1i1i1 1 2 3 ]
UDP::payload replace 0 0 $packetdata
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
UDP::remote_port
Description This command returns the remote UDP port/service number.
Syntax UDP::remote_port
Example Use the following example to use service_group_udp if the UDP remote
port equals 123.
561
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
when CLIENT_ACCEPTED {
if { [UDP::remote_port] == 123 } {
pool service_group_udp
}
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
UDP::respond
Description This command sends the specified data directly to the peer. You can use
this command to complete the protocol handshake.
Example Use the following example if the UDP payload contains one string and
you want to respond with another string.
when CLIENT_DATA {
if { [UDP::payload] contains "asd"] } {
UDP::respond "jkl"
}
}
Example Use the following example to compare the client address to the
network address, then drop if it matches, and send an error message to
the peer.
when CLIENT_DATA {
if { [IP::addr [IP::client_addr] equals [Link]] } {
UDP::drop
UDP::respond "Error: The client is not allowed\r\n"
562
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
}
}
Example Use the following example to initialize the data with the required
binary format and respond to the peer with it.
when CLIENT_ACCEPTED {
set packet [binary format S {0x0000}]
UDP::respond $packet
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
UDP::server_port
Description This command returns the UDP port/service number of the server. This
command is equivalent to the command serverside { UDP::remote_
port }.
Syntax UDP::server_port
Example Use the following example if the UDP server port equals 123, then log it.
when SERVER_CONNECTED {
if { [UDP::server_port] == 123 } {
log "The Server Port is [UDP::server_port]."
}
}
Valid Events
• CLIENT_ACCEPTED
• CLIENT_CLOSED
• CLIENT_DATA
563
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• SERVER_CLOSED
• SERVER_CONNECTED
• SERVER_DATA
564
URI Commands
The following commands can be used to return URI information:
l URI::basename
l URI::decode
l URI::encode
l URI::params
l URI::path
l URI::query
565
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
URI::basename
Description This command returns the basename portion for the designated URI.
For example, given the URI /path/to/[Link]?=param=value,
URI::basename returns [Link]
Example Use the following example to log the basename portion of the URi for
an HTTP request.
when HTTP_REQUEST {
log "The URI Basename is [URI::basename [HTTP::uri]]"
}
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
URI::decode
Description This command returns a decoded version for a specified URI.
Example Decodes a known URL encoded string and logs the output.
when HTTP_REQUEST {
set d "wtf%20%30%31%32"
set e [URI::decode $d]
log "uri decode HTTP_REQUEST:$e"
}
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
566
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
URI::encode
Description This command returns an encoded version of a designated URI.
Example Use the following example to encode the URIs in HTTP requests and/or
responses such that the URI associated with the 404 redirect message is
encoded.
when HTTP_REQUEST {
set HOST [HTTP::host]
}
when HTTP_RESPONSE {
if { [HTTP::status] == 404 } {
HTTP::redirect [Link]
[URI::encode "redirected by $HOST"]
}
}
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
URI::params
Description This command returns the parameters from the URI (Uniform Resource
Identifier) of the current HTTP request.
Example Use the following example to log the query parameters from the URI
when an HTTP request is received:
567
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
when HTTP_REQUEST {
set params [URI::params [HTTP::uri]]
log "Request URI parameters: $params"
}
URI::path
Description This command returns the path portion for a designated URI.
For example, if we specify the URI /path/to/[Link]?=param=value,
and then use the command URI::path, this will return the following
/path/to/.
Example Use the following example to trigger the generation of a log message
containing the path portion for a designated URI.
when HTTP_REQUEST {
set uri [HTTP::uri]
log "$uri path=[URI::path $uri] depth=[URI::path $uri depth]"
}
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
URI::query
Description This command returns the query string portion for a designated URI.
For example, if we specify the URI /path/to/[Link]?=param=value,
the command URI::path returns param=value.
568
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use the following example to trigger the generation of a log message
containing the query parameter with value sent in the URI.
when HTTP_REQUEST {
set query [URI::query [HTTP::uri]]
log "The query portion of the URI is [HTTP::uri]: $query"
}
Valid Events
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_RESPONSE
• HTTP_RESPONSE_DATA
569
URL Commands
The following category commands is supported:
l URL::reputation
570
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
URL::reputation
Description This command returns the URL reputation values.
NOTE:
• It only supports numeric values to do the operations
and the values returns a specific score (from 1-100).
• The require-web-category option is used to enable
run-time-update. This option works with both
HTTP/1.1 and HTTP/2 connections and is only
applicable to HTTP_REQUEST and HTTP_REQUEST_
DATA events.
Valid Events
571
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• AAM_AUTHENTICATION_INIT
• AAM_AUTHORIZATION_INIT
• AAM_AUTHORIZATION_CHECK
• AAM_RELAY_INIT
572
X509 Commands
The following link commands are supported:
l X509::extensions
l X509::hash
l X509::issuer
l X509::not_valid_after
l X509::not_valid_before
l X509::serial_number
l X509::signature_algorithm
l X509::subject
l X509::subject_public_key
l X509::subject_public_key_RSA_bits
l X509::subject_public_key_type
l X509::text
l X509::verify_cert_error_string
l X509::version
l X509::whole
573
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
X509::extensions
Description This command returns the X.509 extensions set on the specified X.509
certificate. If an invalid certificate is supplied, a runtime TCL error is
generated.
Example Use this example for logging and inspecting X.509 certificate extensions
from the client certificate during SSL client authentication.
when CLIENTSSL_CLIENTCERT {
log "The X509 extensions for cert 0 are [X509::extensions
[SSL::cert 0]]."
}
Valid Events
All.
X509::hash
Description This command returns the MD5 (default) or SHA1 hash (fingerprint) of
the specified X.509 certificate.
NOTE: X509::hash no longer returns a text string but the actual hash value as
a Byte array. To return a text string, use the binary scan command. See
the Example 2 below.
574
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use the following example to log the hash for the specified certificate
when complete client request header (method, URI, version, and all
headers, not including the body) is parsed.
Example 1
when HTTP_REQUEST {
log "The X509 hash for cert 0 is [X509::hash [SSL::cert
0]]."
}
Example 2
when CLIENTSSL_CLIENTCERT {
set cert [SSL::cert 0]
set sha256str ""
log "This is the clientcert event"
binary scan [X509::hash sha256 $cert] H* sha256str
log "X509 Hash sha256: $sha256str"
}
Valid Events
All.
X509::issuer
Description This command returns the issuer of the X.509 certificate.
Syntax X509::issuer
Example Use the following example to log the certificate issuer when an SSL
handshake on the client side is completed.
when CLIENTSSL_HANDSHAKE {
log "The X509 issuer for cert 0 is [X509::issuer
[SSL::cert 0]]."
}
Valid Events
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
575
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
X509::not_valid_after
Description This command returns the not-valid-after date of an X.509 certificate.
Syntax X509::not_valid_after
Example Use the following example to log the date when an SSL handshake on
the client side is completed.
when CLIENTSSL_HANDSHAKE {
log "The X509 is not valid after the date of cert 0
[X509::not_valid_after [SSL::cert 0]]."
}
Valid Events
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
X509::not_valid_before
Description This command returns the not-valid-before date of an X.509 certificate.
Syntax X509::not_valid_before
576
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use the following example to log the date when an SSL handshake on
the client side is completed.
when CLIENTSSL_HANDSHAKE {
log "The X509 is not valid before the date of cert 0
[X509::not_valid_before [SSL::cert 0]]."
}
Valid Events
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
X509::serial_number
Description This command returns the serial number of an X.509 certificate.
Syntax X509::serial_number
Example Use the following example to log the serial number when an SSL
handshake on the client side is completed.
when CLIENTSSL_HANDSHAKE {
log "The X509 serial number of cert 0 is [X509::serial_
number [SSL::cert 0]]."
}
Valid Events
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
577
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
X509::signature_algorithm
Description This command returns the signature algorithm of the specified X.509
certificate.
Example Use the following example to log the signature algorithm when an SSL
handshake on the client side is completed.
when CLIENTSSL_HANDSHAKE {
log "The X509 signature algorithm of cert 0 is
[X509::signature_algorithm [SSL::cert 0]]"
}
Valid Events
All.
X509::subject
Description This command returns the subject of an X.509 certificate.
Syntax X509::subject
Example Use the following example to set the certificate subject & log it when an
SSL handshake on the client side is completed.
when CLIENTSSL_HANDSHAKE {
set subject [X509::subject [SSL::cert 0]]
log "The X509 subject of cert 0 is $subject."
}
578
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Valid Events
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
X509::subject_public_key
Description This command returns the subject’s public key of the specified X.509
certificate.
Example Use the following example to log the public key when an SSL client
certificate is received.
when CLIENTSSL_CLIENTCERT {
log "The X509 subject public key for cert 0 is
[X509::subject_public_key [SSL::cert 0]]"
}
Valid Events
All.
X509::subject_public_key_RSA_bits
Description This command returns the size of the subject’s public RSA key of an
X.509 certificate. This command is only applicable when the public key
type is RSA. Otherwise, the command generates an error.
579
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use the following example to log the public key size when an SSL client
certificate is received.
when CLIENTSSL_CLIENTCERT {
log "The X509 RSA public key size of cert 0 is
[X509::subject_public_key_RSA_bits [SSL::cert 0]]."
}
Valid Events
All.
X509::subject_public_key_type
Description This command returns the subject’s public key type of the specified
X.509 certificate. The returned value can be RSA, DSA, or unknown.
Example Use the following example to log the Public Key Algorithm value under
the Subject Public key info for the client certificate at level 0 sent by the
client for authentication.
when CLIENTSSL_CLIENTCERT {
log "x509 subject_public_key_type CLIENTSSL_
CLIENTCERT: [X509::subject_public_key_type [SSL::cert 0]]"
}
Valid Events
All.
X509::text
Description This command returns a certificate in human-readable (text) format.
580
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
Example Use the following example to log the human-readable certificate format
when an SSL client certificate is received.
when CLIENTSSL_CLIENTCERT {
log "The X509 readable text of cert 0 is [X509::text
[SSL::cert 0]]"
}
Valid Events
All.
X509::verify_cert_error_string
Description This command returns the error string as an OpenSSL X.509 error string.
Syntax X509::verify_cert_error_string
Example Use the following example to log the error string and the result code
when an SSL handshake on the client side is completed.
when CLIENTSSL_HANDSHAKE {
log "The X509 verify result of the peer is [X509::verify_
cert_error_string [SSL::verify_result]]."
}
Valid Events
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
581
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
X509::version
Description This command returns the version number of an X.509 certificate.
Syntax X509::version
Example Use the following example to log the certificate version when an SSL
handshake on the client side is completed.
when CLIENTSSL_HANDSHAKE {
log "The X509 version of cert 0 is [X509::version
[SSL::cert 0]]."
}
Valid Events
• CLIENTSSL_CLIENTCERT
• CLIENTSSL_HANDSHAKE
• HTTP_REQUEST
• HTTP_REQUEST_DATA
• HTTP_REQUEST_SEND
• HTTP_RESPONSE
• HTTP_RESPONSE_CONTINUE
• HTTP_RESPONSE_DATA
X509::whole
Description This command returns the entire X.509 certificate in PEM format.
Example Use the following example to log the whole client certificate at level 0
sent to ACOSÆ for client authentication in text form.
when CLIENTSSL_CLIENTCERT {
log "x509 whole CLIENTSSL_CLIENTCERT: [X509::whole [SSL::cert
0]]"
}
Valid Events
582
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
aFleX Commands
All.
583
Deprecated and Disabled Commands
The aFleX scripting language previously supported some commands that are no
longer supported. In addition, though aFleX is based on Tcl, many Tcl commands
have been disabled for security reasons. See the following topics for lists of
deprecated and disabled commands:
l Deprecated aFleX Commands
l Disabled Tcl Commands
584
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Deprecated and Disabled Commands
585
ACOS 7.0.2 aFleX Scripting Language Reference Guide Feedback
Deprecated and Disabled Commands
For a list of previously support aFleX commands that have been deprecated, see
Deprecated aFleX Commands.
586
©2025 A10 Networks, Inc. All rights reserved. A10 Networks, the A10 Networks logo, ACOS, A10 Thunder,
Thunder TPS, A10 Harmony, SSLi and SSL Insight are trademarks or registered trademarks of A10 Networks, Inc. in
the United States and other countries. All other trademarks are property of their respective owners. A10
Networks assumes no responsibility for any inaccuracies in this document. A10 Networks reserves the right to
change, modify, transfer, or otherwise revise this publication without notice. For the full list of trademarks, visit:
Contact Us
[Link]/company/legal/trademarks/.