Information
The 'Max In Progress Sessions Per Client IP' setting in an APM Access Pro?le is a security con?guration that limits the number of simultaneous sessions that can be initiated from a single IP address. This is particularly helpful in preventing a session ?ood, where a hacker might attempt to overwhelm the system by initiating many sessions from a single source. By capping the number of sessions per IP, this setting can help maintain the system's stability and integrity while also providing a layer of protection against such potential attacks.
False positives may result from this setting in networks where users are behind a shared proxy. Sites should conduct operational testing to determine if there are adverse operational impacts. Log reports should be obtained to identify recurring IP sources within the user community.
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.
Solution
Note: Implementation is OPTIONAL. This setting may break some known proxies. Testing should be performed in advance to prevent operational impact.
From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click the Access profile name.
5. In the 'Settings' section, set 'Max In Progress Sessions per Client IP' to 10 or less.
Note: If the setting is grayed out, check the box to the right of the setting and then update it.
6. Click 'Update'.
7. Click 'Apply Access Policy'.