Forum Discussion
Can deactivate this cookie as per audit report -possible impacts
Dear all,
In the audit report , an issue about a BIGip cookie is raised. We think that this security issue is related to the load balancer for environment on preprod and prod who sets automatically this cookie for each client.
As per the report Can we please check if we can deactivate this cookie as recommended in this report ? And what are the possible impacts ?
Need to know is it possible If yes ..what are the possible impacts ??
Thanks in advance
Regards Kamlesh Y
1 Reply
- Kevin_Stewart
Employee
I think the only issue with the default cookie (insert) persistence profile is that it identifies the use of BIG-IP. The cookie is by default named
BIGipServer[pool name]example:
BIGipServermytestpoolYou can absolutely change the name of the persistence cookie to anything you want, with one caveat. The default cookie name includes the assigned pool name, while any name you choose will not. If you're load balancing between multiple pools in a single VIP and using cookie persistence, the default persistence cookie will be able to track each pool individually, while your custom cookie will not.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com