Forum Discussion
imac_105647
Nimbostratus
Jun 23, 2010Application firewalling quandary
This problem is not strictly limited to ASM, but is a more general question:
I am seeing lots of end users type things that throw an exception on the ASM (it's not in blocking mode so I'm ju...
hoolio
Cirrostratus
Jun 23, 2010Hi Ian,
The perfect scenario is if the app uses clientside Javascript to "ask" the user to not enter invalid characters, ASM is blocking with a tight configuration and the app does proper validation of the user input. Then you can keep ASM blocking these types of violations and still give the user a good experience. If you know the app handles validation for these fields successfully, you could relax the ASM charset either for specific parameter values or for all parameter values. If the app doesn't do proper sanitisation of user input, I'd say it's better to block errant user-input and protect the app.
I've heard preliminary discussions of the ability to strip meta-characters from specific parameter values. You might consider talking with your account manager to put in a request for this type of functionality.
Aaron
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects