Forum Discussion
Alexandre_Marko
Nimbostratus
Dec 02, 2011Block access to a pool if url not accessed from a trusted domain
Hello, Here is the problem: We have 2 websites, one with SSL and one in clear. The F5 is ending ths SSL. The 2 websites have their own Virtual Server with their own po...
hoolio
Cirrostratus
Dec 02, 2011I don't think a browser will set a Referer header when transitioning from an HTTPS site to an HTTP site:
http://tools.ietf.org/html/rfc2616section-15.1.3
Clients SHOULD NOT include a Referer header field in a (non-secure)
HTTP request if the referring page was transferred with a secure
protocol.
And the referer header can easily be spoofed, so using it for authorization isn't a secure method.
If the two FQDNs are on the same domain, you could try setting a session cookie on the HTTPS virtual server and store that in a subtable. Then when a request is made to the HTTP virtual server, you could look for the cookie and check it against the subtable entries.
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
