NSF Auto Blocking load balancer

Sany Lv1Posted 2026-May-25 12:06

Hello everyone, or any experts here, I'm having an issue with NSF at my customer. They have a load balancer that's constantly being blocked by NSF. A temporary solution is to add the load balancer's IP address to the whitelist. However, they need to secure the load balancer.

By solving this question, you may help 1004 user(s).

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Muhammad Abid Lv3Posted 2026-Jun-03 13:17
  
Instead of permanently whitelisting the load balancer IP, I would recommend the following troubleshooting steps:

Check the NSF Security Logs and identify which attack signatures, IPS rules, or protection policies are blocking the traffic.
Determine whether the detected traffic is legitimate load balancer traffic or an actual attack.
Capture packets during the blocked sessions to verify the traffic behavior.
If the traffic is legitimate, create a specific exception for the affected signature or protection rule rather than whitelisting the entire IP address.
Review the load balancer configuration for health checks, redirects, NAT, or unusual traffic patterns that may trigger NSF protections.
Update the load balancer firmware and security patches to the latest recommended version.
Verify that the load balancer is not generating malformed packets or excessive connection requests.
Test the changes in a maintenance window and monitor NSF logs to confirm that legitimate traffic is allowed while security protection remains active.
If the issue persists, collect NSF diagnostic logs and open a Sangfor TAC case for further analysis.

This approach helps maintain security protection while reducing false positives instead of bypassing inspection completely through IP whitelisting.
Prosi Lv4Posted 2026-May-25 21:12
  
This only temporarily solves the problem and reduces system visibility and security protection. Identify whether NSF is classifying traffic as malicious and adjust security policies accordingly.

Suggestions: Review/Analyze Detection Logs; Create Appropriate Policy Exceptions; Secure the Load Balancer Itself; Review SSL Inspection Compatibility; Adjust IPS/WAF Policies; Consider Architectural Placement; Capture Traffic for Verification.

The best long-term solution is proper policy tuning and segmentation—not permanent full IP whitelisting.
Muhammad Abid Lv3Posted 2026-May-25 12:40
  
If the load balancer is being continuously blocked by NSF, first check which protection policy or attack signature is triggering the block (IPS, CC attack, WAF, abnormal traffic detection, etc.).

Instead of permanently whitelisting the IP, it is recommended to:

Create a dedicated security policy for the load balancer
Adjust the relevant NSF protection thresholds/signatures
Enable trusted host or exception rules only for necessary services/ports
Verify whether health checks or high connection rates from the load balancer are triggering false positives
Update the NSF signature database and firmware to the latest recommended version


This approach helps maintain security while preventing unnecessary blocking of the load balancer.
Humayun Ahmed Lv4Posted 2026-May-25 12:23
  
First Identify WHAT NSF Is Blocking
NGAF → Logs → Security Logs / NSF Logs

I Can Help:

Change

Moderator on This Board

1
156
3

Started Topics

Followers

Follow

1065
219
100

Started Topics

Followers

Follow

Board Leaders