NGINX App Protect 1.0
Here you can find the release information for F5 NGINX App Protect DoS v1. NGINX App Protect DoS provides behavioral protection against Denial of Service (DoS) for your web applications.
July 6, 2021
- GET and POST flood
- Slowloris, Slowread, Slowpost
- Distributed variations of attacks (see above)
- Challenge Collapsar (CC) attack/random URIs
- HTTP Redirection
- Client-side validation
- TLS fingerprinting
- Traditional HTML-based web applications
- XML-based web services
- REST APIs (JSON)
- Kubernetes Per-pod proxy
- Kubernetes Per-service proxy
- API Gateway
- Traditional edge proxy
- app-protect-dos-24+1.69.6-1.el7.ngx.el7.ngx.x86_64.rpm
- app-protect-dos_24+1.69.6-1~buster_amd64.deb
- app-protect-dos_24+1.69.6-1~bionic_amd64.deb
- app-protect-dos_24+1.69.6-1~focal_amd64.deb
- NGINX Plus R24
-
proxy_request_buffering off
is not supported. -
NGINX App Protect DoS does not protect
grpc
andhttp2
services. The traffic is bypassed. -
TLS fingerprint feature is not used in CentOS 7.4 due to the old OpenSSL version. The required OpenSSL version is 1.1.1 or higher.
-
Slow POST attack always mitigates with block action while other types of attacks can also be mitigated with redirection or JS challenges.