I just tried to setup IP Intelligence policy that is using Feed List. I did all the steps found in docs but still IP defined in my Feed List is not logged or blocked - and I am running out of ideas what could be wrong with my setup.
IP's in Feed List are used to block internal users access to sites in Internet (users are accessing Internet via forward proxy defined on BIG-IP)
Scenario (based on 12.0.0HF1 VE):
After configuring BIG-IP like that I started tests. Results are as described:
Connection is not blocked
Nothing is logged in Security ›› Event Logs : Network : IP Intelligence
iprep_lookup is reporting "iprep_lookup not found for ip"
iRule using IP Reputation is: [IP::reputation [IP::local_addr]] do not detect IP as blocked or belonging to any category
When I am using other IP that is detected by iprep_lookup as belonging to proxy category (see proxy category added to IP Intelligence policy above) in URL it's correctly detected by iRule, connection is blocked, I can see entries in Security ›› Event Logs : Network : IP Intelligence
What is wrong with my configuration?
I would think match override would do the opposite of what is listed in "Action" item defined.
Only way to block given custom IP seems to be add it using IP Intelligence Insert in Security ›› Network Firewall : IP Intelligence : Black List Categories.
When IP (same as defined in Feed List file) is temporary added this way it is indeed blocked by IP Intelligence policy attached to VS.
Some success but still can't make Feed List work :-(
Answering my own question :-)
Feed List is nice feature but hard to troubleshoot :-(.
In my case it turned out that my feed list file encoding was wrong. For some reason when I created feed list file by accident UTF-8 with BOM encoding was used. It adds some garbage to the file.
F5 do not like this garbage at all :-)
I switched to ASCII encoding and everything started to work. Probably UTF-8 without BOM will work as well but I did not have time to test.
Hi Piotr, I have similar issue
-now, can you see the output of "iprep_lookup"?
-Are you using a external http web for feed list? (for example http:/feed.txt)
It was long time ago when I played with this feature. Right now I have no working config to test. Considering second question - yes I used external web server to host feed file, and if I can recall it was working without issue.