For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Zuke_254875's avatar
Zuke_254875
Icon for Altostratus rankAltostratus
Nov 07, 2016

Avoiding cross-domain security restrictions

I have a customer who would like to embed an iframe from a Tableau server on a webpage, without getting cross-domain security restrictions.

 

Currently the tableau server resides behind "tableau.prod.mysite.com." The customer would like traffic that goes to "prod.mysite.com/tableau" to route to "tableau.prod.mysite.com" which the customer thinks will fix the problem.

 

Any suggestions? Thanks!

 

1 Reply

  • I will say firstly that, of course, cross-site protections do exist for a very good reason, so the customer should be quite careful about this.

     

    Having said that, the Host header and Request Target can be transparently rewritten as it traverses the BIG-IP. The following recipe explains what this is, how it is done, and provides an example: