For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

kamlyada_209668's avatar
kamlyada_209668
Icon for Nimbostratus rankNimbostratus
Oct 14, 2015

Can deactivate this cookie as per audit report -possible impacts

Dear all,

 

In the audit report , an issue about a BIGip cookie is raised. We think that this security issue is related to the load balancer for environment on preprod and prod who sets automatically this cookie for each client.

 

As per the report Can we please check if we can deactivate this cookie as recommended in this report ? And what are the possible impacts ?

 

Need to know is it possible If yes ..what are the possible impacts ??

 

Thanks in advance

 

Regards Kamlesh Y

 

1 Reply

  • I think the only issue with the default cookie (insert) persistence profile is that it identifies the use of BIG-IP. The cookie is by default named

    BIGipServer[pool name]
    

    example:

    BIGipServermytestpool
    

    You can absolutely change the name of the persistence cookie to anything you want, with one caveat. The default cookie name includes the assigned pool name, while any name you choose will not. If you're load balancing between multiple pools in a single VIP and using cookie persistence, the default persistence cookie will be able to track each pool individually, while your custom cookie will not.