Comprehensive and Detailed Explanation From BIG-IP Administration — Install, Initial Configuration, and Upgrade:
BIG-IP Self IP addresses have an associated Port Lockdown feature that governs which protocols and services are permitted to communicate directly with that Self IP. By default, Self IPs may allow broader access than desired, making Port Lockdown a critical hardening control.
The Allow Custom option under Port Lockdown is the precise mechanism for administrators who need granular, port-specific filtering. When selected, only the explicitly listed TCP/UDP ports are permitted — all others, including port 443 (HTTPS), are implicitly denied. This satisfies the requirement of blocking 443 specifically while preserving access on other required ports.
The remaining options are incorrect for this scenario:
Option A references SSH access control under System » Platform, which governs management-plane SSH — not Self IP service filtering.
Option B disables the entire Self IP, removing all traffic handling, which is operationally disruptive.
Option D — Allow None — blocks all traffic to the Self IP, not selectively port 443.
The Allow Custom approach provides the surgical precision required: administrators enumerate permitted ports, and everything outside that list — including 443 — is dropped.
Reference Topics: Self IP Port Lockdown, Network Security Hardening, Self IP Configuration — BIG-IP Administration Study Guide.