Forum Discussion

Almassud_221797's avatar
Sep 12, 2015

Web Proxy iRule

Deal iRule experts,

 

I have a need for a web proxy server to block access to the internet. if case you wonder why would I want to do that, then the answer is this is for users who connect to remote desktop service servers since we are having to publish some web applications using internet explorer.

 

so is there a way with or without an iRule to do that?

 

if so, how? :)

 

Thanks MJ

 

4 Replies

  • several web proxy irules have been posted on dev central just do a search. if you need a better solution you can also look at the APM SWG.

     

    but I still don't quite understand your situation. you have remote desktop servers, users and web application. where are these located and how does the BIG-IP fit in to this?

     

  • I apologize for not being as clear as I should have been.

     

    It's basically a farm or remote desktop services servers, and we publish websites that are local to the RDS servers, so no internet access is required for them. So the main concern here is to prevent end users from accessing the internet once on those servers, and one way I know to do that is with a web proxy, but since I have a new pair of F5s, I thought of using them to accomplish that goal.

     

    F5 is not in line, and I was thinking the web proxy would be sort of a VIP that we plug it's IP in the browser and then control and block access to internet.

     

    did that clear it or made it even worst ?

     

  • somewhat clear. but why would you complex things like this? if your users are RDPed to those server just make sure no internet access is possible from those servers period. why add a web proxy to then use that to block access?

     

    if you still want to you can look into several LTM web proxy irules published on dev central.

     

  • boneyard,

     

    I guess, I need this to be scaleable and not only block access to the internet. there might be a case where need to allow a specific group access to the inernet and block the rest.

     

    I took your advice on the search and I found an iApp: https://devcentral.f5.com/codeshare?sid=333

     

    I am testing it out right now.