Forum Discussion
brandon_liew_ch
Nimbostratus
Sep 11, 2013[/apple-touch-icon.png]
HI,
Lately, i saw a lot of traffic drop by the F5 ASM Firewall. As, i am very new to F5 may i know what the reason the F5 detected as - Non-browser Client -
Does it means that mobile user running on ...
brandon_liew_ch
Nimbostratus
Sep 11, 2013Hi, Yes its actually have 0X20..I copy and paste the output here.sorry may i know What do you mean by DC? I have no idea, why the F5 detected it as - Violation - Attack signature detected - Automated client access (http client)
Detected Keywords
Accept-Encoding:0x20gzip0xd0xaConnection:0x20Keep-ALine break live0xd0xaHost:0x20www.xyz.com0xd0xaUser-Line break Agent:0x20Dolphin0x20http0x20client/10.0.3(238)0x20(Line break Android)0xd0xaX-Forwarded-For:0xxx.xx.xx.6Line break 80xd0xa0xd0xa
Torti
Cirrus
Sep 17, 2013Do you now understand, why the ASM see this request as an attack?
It is no "bug", its a feature :-)
You did say "Automated client access (http client)". So, you did explain your problem.
There is an "http client" entry at the User-Agent-Header. If you want to allow Dolphin browser to access your content, you have to deactivate the signature. This browser seems to be to only one containing the string "http client" as part of the User-Agent.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects