Enforcement¶
API Security Local Edition allows you to trigger blocking actions for shadow or unauthorized APIs from the user interface. Enforcement is performed by BIG-IP using its existing security stack. The product does not block traffic directly.
Enforcement workflow¶
The product detects a shadow or unauthorized endpoint through passive traffic analysis.
You select Block in the action menu for the affected endpoint.
The product calls the BIG-IP iControl REST API to update the relevant WAF policy.
BIG-IP enforces the block using its security stack.
Block an endpoint¶
To block a shadow or unauthorized endpoint:
Open the per-domain inventory.
Locate the endpoint.
In the Action column, open the action menu and select the block action.
Confirm the action when prompted.
Prerequisites for enforcement¶
Before enforcement actions can succeed, the following must be in place:
The target BIG-IP device must be registered for management connectivity. See Register a BIG-IP device for management in the API Security Local Edition Admin Guide.
The Web Application Firewall (WAF) policy on BIG-IP must be configured correctly. For specific WAF configuration requirements, see Known issues in the API Security Local Edition Release Notes.
If a block action fails, contact your administrator. See also Common issues below.