Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

Rate Limit

From Tech-Wiki


F5 BIG-IP iRule example that rate-limits requests to /auth/login by tracking source addresses in the session table and temporarily shunning clients that exceed the threshold.

Behaviour

The example uses three values:

  • timeoutvalue — how long request entries remain in the per-source table.
  • maxattempts — maximum requests allowed in that window.
  • shuntimeout — how long an address remains in the shun table.
!
Source-IP rate limiting can affect shared clients
Multiple legitimate users may appear behind the same NAT/proxy address. Test thresholds and client-address selection carefully before enforcing the iRule in production.

iRule

when HTTP_REQUEST {
  #timeoutvalue is how long requests stay in the auth attempts table
  set timeoutvalue 30
  #maxattempts is the number of requests that can happen within the timeoutvalue before being shunned
  set maxattempts 20
  #shuntimeout is the time that the source IP will be blocked once it gets shunned
  set shuntimeout 60
 
  #reset every request if in shun table
  if { [table lookup -subtable "shun" [IP::client_addr]] > 0 } {
   table incr -subtable "shun" [IP::client_addr]
   set totaldrops [table lookup -subtable "shun" [IP::client_addr]]
   reject
   #log local0. "SHUN - Reset connection from [IP::client_addr] - Total: $totaldrops"
   return
  }
 
  if { ( [string tolower [HTTP::uri]] equals "/auth/login" ) } {
    #placeholder- send back fake auth response if in shun table
 
   #create large random number to act as an approx unique key - key collisions are not too detrimental
   set randkey [expr { int(100000000 * rand()) } ]
   #log local0. "URI match: created random key $randkey, adding to subtable for [IP::client_addr]"
   table set -subtable [IP::client_addr] $randkey 1 $timeoutvalue
 
   if { [table keys -subtable [IP::client_addr] -count] > $maxattempts} {
    log local0. "auth rate exceeded for [IP::client_addr], adding IP to shun table. Will unblock if no new conns for $shuntimeout seconds"
    #add source IP to the shun table with value of 1
    #note, this specific request was not blocked, but new connections from same src IP will be blocked on next request
    table set -subtable "shun" [IP::client_addr] 1 $shuntimeout
   }
  }
 }

See also