DoS TPS-Based mitigation: how it works in details?

I have a DoS profile with enabled TPS-based mode.

I configured it by src IP, GeoIP, URL and by site with different TPS criteria. I'm using only Request Block method of mitigation.

Question: how F5 should try to mitigate attack which exceed TPS criteria eg. by GeoIP? - strike up for blocking all src IP from suspicious GeoIP or any more specific activity? How it works in relation with "Escalation period"?

Replies to this Discussion


Try this ASM DoS Profile

Comments on this Reply
Comment made 22-Aug-2016 by rezos 55

Excellent slide deck! Thanks you!

Comment made 22-Aug-2016 by boneyard 5579

if that answered your question please flag it as such.