Get started with Bot Defense
Bot Defense protects your web and mobile application endpoints from automated attacks by identifying and mitigating malicious or bad bots. For more information about Bot Defense features, see Bot Defense Overview.
Important: Bot Defense self-service policy management is an early access feature.
The following sections explain how to get started with Bot Defense:
- Sign Up for Bot Defense
- Decide what you want to protect
- Configure your Bot Defense infrastructure
- Configure your bot policies
- Test your configuration
- Deploy policies in your production infrastructure
- Enable Bot Defense on an HTTP load balancer
- Deploy Bot Detection rules
Sign Up for Bot Defense
To enable Bot Defense, contact your F5 account team. Once enabled, you can use Bot Defense Self-Service Policy Management to configure the system.
Bot Defense Self-Service Policy Management is available from the Distributed Cloud Console. You must have one or more of the following roles:
- f5xc-bot-defense-admin: Provides advanced administrative access, including service activation.
- f5xc-bot-defense-user: Provides read and write access to bot policies and read access to bot infrastructure. This role also grants permission to deploy new bot policy versions.
- f5xc-bot-defense-monitor: Provides read-only access to bot infrastructure, bot policies and dashboards.
- f5xc-bot-defense-report: Provides permissions to create and manage monthly Bot Defense reports.
If you do not have any of these roles, contact your Bot Defense administrator or F5 Support.
Decide what you want to protect
You must decide which web and mobile endpoints you want to protect with Bot Defense. See the following information:
Configure your Bot Defense infrastructure
Use the Distributed Cloud Console to add and configure your Bot Defense infrastructures in the F5 Hosted Cloud. Bot Defense infrastructures are the virtual machines that host the Bot Defense components that process and evaluate your traffic to determine what traffic is human and what is bots.
Important: If F5 Operations has already configured your Bot Defense infrastructure, go to Configure Your bot policies.
Important: If you use Bot Defense in API mode, you cannot use self-service to create your Bot Defense infrastructure. You must contact F5 Support or your Sales team to create your infrastructure.
A typical Bot Defense deployment can consist of multiple Test and Production infrastructures. You must configure different infrastructures for web-based traffic and mobile traffic. You can add as many Production and Test infrastructures as your subscription limit allows.
To configure a Bot Defense infrastructure, you must configure the following settings:
- Traffic type: Whether you want the infrastructure to process mobile or web-based traffic.
- Infrastructure type: Whether the infrastructure is for production traffic or is for testing.
- Region: The geographic region where you want your infrastructure located. For production infrastructures, you must choose two regions.
- Access control list: The list of IP addresses from which traffic can access the new infrastructure.
For instructions, see Configure the Bot Defense infrastructure.
Configure your bot policies
Bot Defense provides three system policies that allow you to control system configuration settings:
Use Bot Defense self-service policy management to make and deploy changes to your policies to protect new endpoints, update mitigation actions, and so on. You must configure different policies for web-based traffic and for mobile traffic.
Important: F5 strongly recommends that you deploy and thoroughly test policy updates in your Test infrastructure before you deploy in your Production infrastructure.
Note: If you use Bot Defense in API mode, you do not need to configure the Bot Network Policy.
Use the Distributed Cloud Console to view and manage your policies, including details of current and past policy versions.
Test your configuration
Deploy your policies in your Test infrastructure to test your Bot Defense deployment and confirm that:
- You properly configured Bot Defense policies.
- Bot Defense injects JavaScript tags in your application pages correctly.
- You correctly integrated the F5 Distributed Cloud Mobile SDK.
For information about how to deploy your Bot Defense policies, see Deploy policy updates.
For information about how to test Bot Defense, see Test your Bot Defense configuration.
Deploy policies in your production infrastructure
Important: F5 strongly recommends that you deploy and thoroughly test policy updates in your Test infrastructure before you deploy in your Production infrastructure.
After you verify in your Test infrastructure that Bot Defense is configured correctly and correctly identifies automated traffic, you can deploy your policies yourself or work with your F5 team to deploy your policies in your Production infrastructure.
Enable Bot Defense on an HTTP load balancer
You can enable Bot Defense on one or more HTTP load balancers in either the Web App & API Protection workspace or the Multi-Cloud App Connect workspace. To configure Bot Defense on an HTTP load balancer, you must complete the following tasks on each HTTP load balancer where you want to enable Bot Defense:
- Enable the Bot Defense workspace on one or more HTTP load balancers.
- Configure how you want Bot Defense to inject JavaScript tags in the HTTP pages in your application. Bot Defense adds JavaScript, which runs in users' browsers and collects data that distinguishes between human visitors and automation.
- To protect mobile endpoints, enable and configure the Distributed Cloud Mobile SDK. The Mobile SDK collects telemetry that is then inspected by Bot Defense to determine if requests initiated from legitimate mobile devices.
For instructions, see Configure Bot Defense on an HTTP load balancer.
Deploy bot detection rules
Important: Bot detection rule self-service management is a limited availability feature. Contact your F5 account team for information.
When you sign up for Bot Defense, F5 provides a set of bot detection rules. A bot detection rule contains criteria that Bot Defense uses to determine whether a transaction is from a human or automated source. A subset of rules is turned on by default. The remaining rules are turned off.
Monitor your traffic for approximately two weeks to see how rules that are turned on affect your traffic. After this initial two weeks, you can begin to turn rules on and off to make changes to how Bot Defense handles your traffic. You can make these changes in the Distributed Cloud Console without contacting F5 for assistance.
Important: F5 recommends that you deploy each rule in a Test infrastructure before you deploy in your production infrastructure.
For information about bot detection rules, see Bot detection rules overview.