SCHIZOSCHIZOSCHIZO
  • WORK
  • ABOUT
  • BRAIN DUMP
  • TOOLS
  • CONTACT
2026-06-06

F5 Local Traffic Policies

f5bigipiRulesload balancingtraffic

Local traffic policies comprise a prioritized list of rules that match defined conditions and run specific actions, which you can assign to a virtual server that directs traffic accordingly.

Creating a local traffic policy

  1. >On the Main tab, click Local Traffic > Policies > Policy List.
  2. >Click Create.
  3. >In the Name field, type a unique name for the policy.
  4. >From the Strategy list, select a matching strategy.
  5. >For the Requires setting, select a protocol entry from the Available list, and move the entry to the Selected list using the Move button.
  6. >For the Controls setting, select a functional area or module from the Available list, and move the entry to the Selected list using the Move button.
  7. >Click Add.
  8. >In the Rule field, type a unique name for the rule.
  9. >Using the Conditions setting, configure the applicable options.
    1. >From the Operand list, select an operand.
    2. >From the Event list, select an event.
    3. >From the Selector list, select the applicable setting.
    4. >Select the Negate check box to reverse the policy conditions.
    5. >From the Condition list, select a condition.
    6. >Select the case sensitive check box to apply case sensitivity to the condition.
    7. >In the Values field, type the text that applies to the condition and click Add.
    8. >To the left, near the Missing setting, click Add.
  10. >Using the Actions setting, configure the applicable options.
    1. >From the Target list, select a target.
    2. >From the Event list, select an event.
    3. >From the Action list, select an action.
    4. >From the Parameters list, select a type of parameter to apply.
    5. >In the Parameters field, type the text that applies to the type of parameter and click Add.
    6. >At the lower left, click Add.
  11. >Click Finished.

About strategies for local traffic policy matching

Each BIG-IP local traffic matching policy requires a matching strategy to determine the rule that applies if more than one rule matches. The BIG-IP policies provide three policy matching strategies: first-match, best-match, and all-match. Each policy matching strategy prioritizes rules according to the rule's position within the Rules list.

Note: a rule without conditions becomes the default rule in a best-match or first-match strategy, when the rule is the last entry in the Rules list.

Matching strategyDescription
First-match strategyA first-match strategy starts the actions for the first rule in the Rules list that matches.
Best-match strategyA best-match strategy selects and starts the actions of the rule in the Rules list with the best match, as determined by: the number of conditions and operands that match the rule; the length of the matched value for the rule; the priority of the operands for the rule. Note: in a best-match strategy, when multiple rules match and specify an action, conflicting or otherwise, only the action of the best-match rule is implemented.
All-match strategyAn all-match strategy starts the actions for all rules in the Rules list that match. Note: in an all-match strategy, when multiple rules match but specify conflicting actions, only the action of the best-match rule is implemented.

Local traffic policy matching Requires profile settings

Requires SettingDescription
httpSpecifies that the policy matching requires an HTTP profile.
sslSpecifies that the policy matching requires a Client SSL profile.
tcpSpecifies that the policy matching requires a TCP profile.

Local traffic policy matching Controls settings

Controls SettingDescription
accelerationProvides controls associated with acceleration functionality.
cachingProvides controls associated with caching functionality.
classificationProvides controls associated with classification.
compressionProvides controls associated with HTTP compression.
forwardingProvides controls associated with forwarding functionality.
request-adaptationProvides controls associated with request-adaptation functionality.
response-adaptationProvides controls associated with response-adaptation functionality.
server-sslProvides controls associated with server-ssl functionality.

About rules for local traffic policy matching

BIG-IP local traffic policy rules match defined conditions and start specific actions. You can create a policy with rules that are as simple or complex as necessary, based on the passing traffic. For example, a rule might simply determine that a client's browser is a Chrome browser that is not on an administrator network. Or a rule might determine that a request URL starts with /video, that the client is a mobile device, and that the client's subnet does not match 172.27.56.0/24.

About conditions for local traffic policy matching

The conditions for a local traffic policy rule define the necessary criteria that must be met in order for the rule's actions to be applied. For example, a policy might include the following conditions, which, when met by a request, would allow the rule's specified actions to be applied.

ConditionSetting
Operandhttp-host
Eventrequest
Selectorall
Conditionequals
Valueswww.siterequest.com

Local traffic policy matching Conditions operands

OperandTypeValid EventsSelectors and ParametersDescription
client-sslstring/numberrequest, responsecipher, cipher-bits, protocolRequires a Client SSL profile for policy matching.
http-basic-authstringrequestpassword, usernameReturns <username>: <password> or parts of it.
http-cookiestringrequestall, nameReturns the value of a particular cookie or cookie attribute.
http-headerstringrequest, responseall, name (required)Returns the value of a particular header.
http-hoststring/numberrequestall, host, portProvides all or part of the HTTP Host header.
http-methodstringrequestallProvides the HTTP method.
http-refererstring/numberrequestall, extension, host, path, path-segment, port, query-parameter, query-string, scheme, unnamed-query-parameterProvides all or part of the HTTP Referer header.
http-set-cookiestringresponsedomain, expiry, path, value, versionSets the selected setting of a particular cookie or cookie attribute.
http-statusstring/numberresponseall, code, textReturns the HTTP status line or part of it.
http-uristring/numberrequestall, extension, host, path, path-segment, port, query-parameter, query-string, scheme, unnamed-query-parameterProvides all or part of the request URI.
http-versionstring/numberrequest, responseresponse, all, major, minor, protocolProvides HTTP/1.1 as a number.
tcpnumberrequest, responseaddress, mss, port, route-domain, rtt, vlan, vlan-idRequires a TCP profile for policy matching.

About actions for a local traffic policy rule

The actions for a local traffic policy rule determine how traffic is handled. For example, actions for a rule could include: blocking traffic, rewriting a URL, logging traffic, adding a specific header, redirecting traffic to a different pool member, or selecting a specific Web Application policy.

Local traffic policy matching Actions operands

TargetTypeValid EventsAction
accelerationstring/numberrequestdisable, enable
cachestringrequest, responsedisable, enable, pin
compressstringrequest, responsedisable, enable
decompressstringrequest, responsedisable, enable
forwardstringrequestreset, select (clone-pool, member, nexthop, node, pool, rateclass, snat, snatpool, vlan, vlan-id)
http-cookiestringrequestinsert (name, value), remove (name)
http-headerstring/numberrequest, responseinsert (name, value), remove (name), replace (name, value)
http-hoststringrequestreplace (value)
http-refererstringrequestinsert (value), remove, replace (value)
http-replystringrequest, responseredirect (location)
http-set-cookiestring/numberresponseinsert (name, value, domain, path), remove (name)
http-uristring/numberresponsereplace (path, query-string, value)
logstring/numberrequest, responsewrite (message)
pemstring/numberrequest, responseclassify (application, category, defer, protocol)
request-adaptstring/numberrequest, responsedisable, enable
response-adaptstring/numberrequest, responsedisable, enable
server-sslstring/numberrequestdisable, enable
tclstring/numberrequest, responseset-variable (name, expression)
tcp-naglestring/numberrequestdisable, enable
Matching strategies3 blanks

A strategy runs the first rule that matches, a strategy runs the best-matching rule, and an strategy runs every rule that matches.

try it before revealing
QSelf-check
Which operand returns all or part of the HTTP Host header, and on which event?
click to reveal the answer
AAnswer
http-host, on the request event. Its selectors are all, host and port.
Answer it in your head first, then reveal.

Read next

  • 2026-06-25 · CheatsheetsSSL Offloading on F5 BIG-IP
  • 2026-06-25 · Byte-SizedLocking Down Ports on F5 BIG-IP
  • 2026-06-17 · ChecklistsConfiguring DNSSEC on F5 BIG-IP DNS
  • 2026-06-11 · CheatsheetsInstalling NGINX Plus

← All PostsSCHIZO Brain Dump
SCHIZO

Suhesh Kasti — AppSec & Offensive Security

Navigate

  • ▸ Projects
  • ▸ Brain Dump
  • ▸ Cyber Tools
  • ▸ About
  • ▸ Contact
  • Download CV

Connect

  • ◆ GitHub
  • ◆ LinkedIn
  • ◆ Twitter
  • ◆ YouTube
  • ◆ Telegram
© 2026 SCHIZO

Press / to search