F5 Local Traffic Policies
Local traffic policies comprise a prioritized list of rules that match defined conditions and run specific actions, which you can assign to a virtual server that directs traffic accordingly.
Creating a local traffic policy
- >On the Main tab, click Local Traffic > Policies > Policy List.
- >Click Create.
- >In the Name field, type a unique name for the policy.
- >From the Strategy list, select a matching strategy.
- >For the Requires setting, select a protocol entry from the Available list, and move the entry to the Selected list using the Move button.
- >For the Controls setting, select a functional area or module from the Available list, and move the entry to the Selected list using the Move button.
- >Click Add.
- >In the Rule field, type a unique name for the rule.
- >Using the Conditions setting, configure the applicable options.
- >From the Operand list, select an operand.
- >From the Event list, select an event.
- >From the Selector list, select the applicable setting.
- >Select the Negate check box to reverse the policy conditions.
- >From the Condition list, select a condition.
- >Select the case sensitive check box to apply case sensitivity to the condition.
- >In the Values field, type the text that applies to the condition and click Add.
- >To the left, near the Missing setting, click Add.
- >Using the Actions setting, configure the applicable options.
- >From the Target list, select a target.
- >From the Event list, select an event.
- >From the Action list, select an action.
- >From the Parameters list, select a type of parameter to apply.
- >In the Parameters field, type the text that applies to the type of parameter and click Add.
- >At the lower left, click Add.
- >Click Finished.
About strategies for local traffic policy matching
Each BIG-IP local traffic matching policy requires a matching strategy to determine the rule that applies if more than one rule matches. The BIG-IP policies provide three policy matching strategies: first-match, best-match, and all-match. Each policy matching strategy prioritizes rules according to the rule's position within the Rules list.
Note: a rule without conditions becomes the default rule in a best-match or first-match strategy, when the rule is the last entry in the Rules list.
| Matching strategy | Description |
|---|---|
| First-match strategy | A first-match strategy starts the actions for the first rule in the Rules list that matches. |
| Best-match strategy | A best-match strategy selects and starts the actions of the rule in the Rules list with the best match, as determined by: the number of conditions and operands that match the rule; the length of the matched value for the rule; the priority of the operands for the rule. Note: in a best-match strategy, when multiple rules match and specify an action, conflicting or otherwise, only the action of the best-match rule is implemented. |
| All-match strategy | An all-match strategy starts the actions for all rules in the Rules list that match. Note: in an all-match strategy, when multiple rules match but specify conflicting actions, only the action of the best-match rule is implemented. |
Local traffic policy matching Requires profile settings
| Requires Setting | Description |
|---|---|
| http | Specifies that the policy matching requires an HTTP profile. |
| ssl | Specifies that the policy matching requires a Client SSL profile. |
| tcp | Specifies that the policy matching requires a TCP profile. |
Local traffic policy matching Controls settings
| Controls Setting | Description |
|---|---|
| acceleration | Provides controls associated with acceleration functionality. |
| caching | Provides controls associated with caching functionality. |
| classification | Provides controls associated with classification. |
| compression | Provides controls associated with HTTP compression. |
| forwarding | Provides controls associated with forwarding functionality. |
| request-adaptation | Provides controls associated with request-adaptation functionality. |
| response-adaptation | Provides controls associated with response-adaptation functionality. |
| server-ssl | Provides controls associated with server-ssl functionality. |
About rules for local traffic policy matching
BIG-IP local traffic policy rules match defined conditions and start specific actions. You can create a policy with rules that are as simple or complex as necessary, based on the passing traffic. For example, a rule might simply determine that a client's browser is a Chrome browser that is not on an administrator network. Or a rule might determine that a request URL starts with /video, that the client is a mobile device, and that the client's subnet does not match 172.27.56.0/24.
About conditions for local traffic policy matching
The conditions for a local traffic policy rule define the necessary criteria that must be met in order for the rule's actions to be applied. For example, a policy might include the following conditions, which, when met by a request, would allow the rule's specified actions to be applied.
| Condition | Setting |
|---|---|
| Operand | http-host |
| Event | request |
| Selector | all |
| Condition | equals |
| Values | www.siterequest.com |
Local traffic policy matching Conditions operands
| Operand | Type | Valid Events | Selectors and Parameters | Description |
|---|---|---|---|---|
| client-ssl | string/number | request, response | cipher, cipher-bits, protocol | Requires a Client SSL profile for policy matching. |
| http-basic-auth | string | request | password, username | Returns <username>: <password> or parts of it. |
| http-cookie | string | request | all, name | Returns the value of a particular cookie or cookie attribute. |
| http-header | string | request, response | all, name (required) | Returns the value of a particular header. |
| http-host | string/number | request | all, host, port | Provides all or part of the HTTP Host header. |
| http-method | string | request | all | Provides the HTTP method. |
| http-referer | string/number | request | all, extension, host, path, path-segment, port, query-parameter, query-string, scheme, unnamed-query-parameter | Provides all or part of the HTTP Referer header. |
| http-set-cookie | string | response | domain, expiry, path, value, version | Sets the selected setting of a particular cookie or cookie attribute. |
| http-status | string/number | response | all, code, text | Returns the HTTP status line or part of it. |
| http-uri | string/number | request | all, extension, host, path, path-segment, port, query-parameter, query-string, scheme, unnamed-query-parameter | Provides all or part of the request URI. |
| http-version | string/number | request, response | response, all, major, minor, protocol | Provides HTTP/1.1 as a number. |
| tcp | number | request, response | address, mss, port, route-domain, rtt, vlan, vlan-id | Requires a TCP profile for policy matching. |
About actions for a local traffic policy rule
The actions for a local traffic policy rule determine how traffic is handled. For example, actions for a rule could include: blocking traffic, rewriting a URL, logging traffic, adding a specific header, redirecting traffic to a different pool member, or selecting a specific Web Application policy.
Local traffic policy matching Actions operands
| Target | Type | Valid Events | Action |
|---|---|---|---|
| acceleration | string/number | request | disable, enable |
| cache | string | request, response | disable, enable, pin |
| compress | string | request, response | disable, enable |
| decompress | string | request, response | disable, enable |
| forward | string | request | reset, select (clone-pool, member, nexthop, node, pool, rateclass, snat, snatpool, vlan, vlan-id) |
| http-cookie | string | request | insert (name, value), remove (name) |
| http-header | string/number | request, response | insert (name, value), remove (name), replace (name, value) |
| http-host | string | request | replace (value) |
| http-referer | string | request | insert (value), remove, replace (value) |
| http-reply | string | request, response | redirect (location) |
| http-set-cookie | string/number | response | insert (name, value, domain, path), remove (name) |
| http-uri | string/number | response | replace (path, query-string, value) |
| log | string/number | request, response | write (message) |
| pem | string/number | request, response | classify (application, category, defer, protocol) |
| request-adapt | string/number | request, response | disable, enable |
| response-adapt | string/number | request, response | disable, enable |
| server-ssl | string/number | request | disable, enable |
| tcl | string/number | request, response | set-variable (name, expression) |
| tcp-nagle | string/number | request | disable, enable |
A strategy runs the first rule that matches, a strategy runs the best-matching rule, and an strategy runs every rule that matches.