-
[T&C] Thunder ADC with Thunder Kubernetes Connector (TKC) using CRDs
In an earlier article, we saw how you can use the Thunder Kubernetes Connector (TKC) to dynamically configure the Thunder ADC for load-balancing traffic to a Kubernetes cluster. In that article, we specified the SLB configuration using annotations in an Ingress resource. Starting from TKC v1.11, Thunder Kubernetes…
-
Why does A10 device send ARP attack?
Our switch received an ARP attack alarm from A10 device.And the SourceAttackIP 202.104.30.228 is deployed on our A10. What is the original cause of this? Aug 8 2022 19:09:34+08:00 GDSD-BDC-INT-CR01 %%01SECE/4/SPECIFY_SIP_ATTACK(l)[12]:The specified source IP address attack occurred. (Slot=MPU,…
-
Need help to config DNS static entry on GSLB.
From the ADC datasheet ACOS ADC support DNS RPZ (response policy zone). We have a10 thunder boxes acting as GSLB controller/device and would like to move few thousands static dns entries from the old dns server to A10. For now each static entry is a GSLB service-ip with health-check disable, attach to a site name PRIVATE…
-
F5 automap feature
Hi, I have one F5 with irule contain "automap snat", this functionality allows changing the IP when the destination is local to one of the F5 in order to prevent asymmetric routing. The automap options tells to BIG-IP to decide what source ip to use to reach the destination network. I rule like this when CLIENT_ACCEPTED {…
-
Changing the IP address of the management interface in the VCS.
Hello! There are 2 A1030S, VCS is enabled. You need to change the address of the management interface. How to do it correctly? Through the CLI? What is the sequence?
-
Balance HTTPS traffic(without decryption)
Hi all! The task is to balance HTTPS traffic to 2 servers (TLS1 + TLS2), without decryption. How to configure the virtual server correctly in this case? The TLS|SSL processing itself will continue on TLS1+TLS2, i.e. you only need to do balancing 1.slb virtual-server VIP_HTTPS 192.168.195.2 port 443 https source-nat pool…
-
"Address already used for an interface" when changing IP address VIP
Hello, I need to change the address of the virtual server, it gives such an error. Reboot does not help.
-
Service IP unknown
Hello, I would like you to guide me a little. I have configured a site with GSLB and regarding the Service IP, when the configuration is finished the IP shows it in unknown state in the GUI, but it does respond to the ping. What can be happening? Is it missing to add something in the GSLB configuration? Thank you
-
Configure 3 sites with HTTPS and Wildcard Certificate
Hello, I need your help. We are setting up 3 GSLB websites which are set up with a wildcard certificate. So far only 2 websites work and one does not work since it throws an unsafe site. Added Client SSL and Server SSL, but a pool that has a real server with HTTP port 8080 appears as a non-secure site. If I remove the SSL…
-
Thunder A1040s - load balancer
Does Thunder A1040s supports reverse proxy? thanks.
-
Reverse Proxy Incoming connection - distribute to different servers
Hi everyone, Is it possible to achieve this, as per my Title? A reverse proxy for an incoming connection and distribute or assign to different servers? The outgoing connection for the servers will be proxied before being forwarded to the internet. And it can be done using Python? Thanks in advance.
-
Upgrade 1030S - 2.7 to 4.1
Hello. I trying to update TH1030S running 2.7.1 to 4.1.1 but this error: "Please ensure enough space left in disk, a file system error was detected on the ACOS Web Server." PS: I tried via CLI/tftp and WEB. Any idea?
-
Inter partition Routing
Hello I am trying to do a Inter partition Routing, i did two lv3 partitions, one partition has 1 port with the network 10.0.0.0/24 and the other partition has other port with the network 11.0.0.0/24 but when i do a ping it says network unreachable ! partition P_IPSEC-1 id 5 application-type adc ! partition P_VXLAN-1 id 6…
-
Retrieve the highest number of requests
If I want to add one more rule which is to black list the highest number of DNS query when the total number of DNS queries exceed the threshold value (i.e. $totalcount). How can I retrieve the IP address which has the highest number of DNS query? set totalcount [table incr tmp_table [IP::client_addr]] if { $totalcount >…
-
What should be the format of class list for IPv4 and FQDNs
I've have been trying to create class lists for IPv4 and FQDNs by importing files hosted on a separate web server. What should be the format of the data in the files? I tried the following but keep getting the error "invalid format at line 1". Is the format below correct for FQDNs What should be the format for IPv4? str…
-
total connections
I want to see the total number of connections per VS server in a period of time in A10, how to view ?(for example, what is the total number of connections per IP in the past month)
-
Routing Traffic Via Inactive VRRP-A Machine
Hello everyone, since we're seeing weird timeouts to external services with any of the more recent versions greater than 5.2.1-p2, support suggested to set up some sort of debug environment for them to check. Is it possible to route traffic from physical servers via a virtual ethernet interface on the inactive machine…
-
Redirect 302 with aFlex
Hello, I need your help and knowledge on A10 with aFlex. I am trying to create a 302 redirect for a site that is published on the internet but when testing the redirect it does not execute it, this is my code so that you can guide me: when HTTP_REQUEST { if {[HTTP::host] == "https://recargaweb.imperial.com/" } {…
-
Block harmful traffic or attack via Websocket traffic
Hi Experts, We have a web server is running some services via Websocket traffic. Now we want to block harmful traffic, attacks like SQL Injection, XSS... like the WAF template works with HTTP traffic, but now is WebSocket traffic. Could you give me a detail aflex script or WAF template to do that. (One more point, we…
-
CGNAT + VRRP-A
Hi everyone, I have a new challenge and it is the following I have a CGNAT solution already implemented in datacenter #1 but they bought another appliance and they are going to put it in datacenter #2 which is several kilometers away. So I was assigned the task of configuring the VRRP-A solution between the two appliances…
-
Control CPU reaches 100 percent
Dear All, I m using A10 Thunder 1040. I observed that Control CPU is reaching 100 %. Please define What is control cpu? what is data cpu? How do I limit Control CPU for reaching 100 %. Would there be any impact on ADC functionality in case of 100% control CPU? Waiting for reply.
-
[T&C] Deploy NAT64 and DNS64 with Thunder CGN/CFW
In this article, we will see how you can deploy NAT64 with DNS64 using Thunder CGN/CFW to enable IPv6 clients to access IPv4 resources. Setup Here is an overview of the setup and the overall functionality (DNS64 and NAT64): Base configuration Here we have the following base configuration on the Thunder device: ip dns…
-
ospf filter routes
Dear community, I have a scenario where one CGN have two internal routers with OSPF, each one have his own process ospf in the CGN, both routers publish one network in commun with the same distance and metric. The CGN select one of them to put in FIB, but, we need to put in FIB table the route anonced by the second router…
-
[T&C] Use Postman for A10 aXAPI calls
Postman is well known test tool and very convenient when it comes to executing APIs. It provides not only variety of API functionality including authentication, setting headers, customizing the payload, but also collaboration functionality for the teams dealing with API projects. This article explains how you can use…
-
Virtual Server with 443 (HTTPS)
Dear, I am new to A10 and I need to create a virtual server with a service group and its real servers in 443. When I finish the configuration and test the site in the browser, it gives me the following: bad request Your browser sent a request that this server could not understand. Reason: You're speaking plain HTTP to an…
-
AxAPI Export or Download example?
I'm wanting to snag the fixed-nat port mapping file periodically and save it elsewhere, or in a database. I have managed to get the list of files, but I can't seem to figure out the export command. Could someone by chance share an example of how this would be done? In a perfect world i'd like to hit the API, get the file…
-
How to set up Harmony Controller ?
In this article, we will look at how to set up Harmony Controller after activating Controller and Thunder licenses. The next steps are to: 1. Check Networking Pre-requisites 2. On-board Thunder to Harmony Controller 3. Viewing Analytics and Insights Step 1: Check Networking Pre-requisites Communication between Harmony…
-
How to get started with vThunder Free trial ?
In this article, we will look into how you can sign-up & quickly set up your vThunder free trial in 30 minutes. This trial allows you to explore and test the benefits of A10 application service capabilities Convergent Firewall (CFW), Application Delivery Controller (ADC), Carrier Grade Networking (CGN), and SSL Insight…
-
virtual-server with two service-group
Hi team I've a virtual server with a specify IP, but I need associate differentes service-group because the service will be use always the same IP. How I can associate for the same port (in my case 80) differents service-group for SLB? Thank you
-
CVE-2022-0778
A10 PSIRT says: To mitigate this issue for ACOS management plane, avoid importing / exporting files using the HTTPS transfer method. Does it include GUI operation, which ACOS works as HTTPS server and does not verify certification and accept EC parameters either.