Forum Discussion
AWAF block a list of parameters values
Rather than block disallowed values, if you know what the allowed values are, you can create a static content value parameter that includes those values. Any other values would be disallowed.
If all you know are the values that are NOT allowed, you should be able to create a custom attack signature and attack signature set that includes those disallowed value strings. You can then add the parameter to the policy (manually or via learning), and then add the attack signature set to that specific parameter.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
