Forum Discussion
ASM and ADFS
Hi
I am deploying LTM for balancing ADFS. As ADFS is using https customer has asked if ASM inspection is possible and if it would add any value.
Is anybody able to help answer to this?
Thanks in advance
- nathe
Cirrocumulus
Paul, I haven't done this myself, but my general opinion is if a http(s) service is published on the internet then a WAF will, in most cases, offer some protection and I would recommend it. This would be to prevent against known http rfc violations and general attacks, like xss.
A quick search on ADFS vulnerabilities returned this CVE which is a XSS vulnerability. So, a WAF in a purely negative model of security would help.
Hope this helps,
N
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com