Forum Discussion
carolyndiep_163
Nimbostratus
Dec 02, 2015Difference between APM Cookie Options & ASM Cookie Properties
I noticed recently that in both APM and ASM, there is the ability to configure cookie options like Secure Flag and HTTP Only. Does anyone know the difference between how each module handles these coo...
Lucas_Thompson_
Dec 02, 2015Historic F5 Account
The APM options are used to modify the APM cookies that are used for APM session management (MRHSession). The ASM options are used to modify other cookies traversing ASM.
I don't know if there is really a precedence issue here since the targets for the options are different. APM comes before ASM, so ASM settings shouldn't modify the APM cookies coming from the same BIG-IP.
- carolyndiep_163Dec 02, 2015
Nimbostratus
Thanks for the reply Lucas. Anyway you can be more specific on your comment about "other cookies" that would traverse ASM? I didn't realize there was more than just a session cookie involved. - Lucas_Thompson_Dec 02, 2015Historic F5 AccountASM has cookies that itself to identify flows vs users, so there are settings for that. They're covered here: https://support.f5.com/kb/en-us/solutions/public/13000/700/sol13787.html Separately, ASM has security options to modify *other* application cookies, like from an HTTP service being protected by ASM. So, those cookies are not set by ASM itself. Rather, ASM is modifying 3rd party cookies.
- carolyndiep_163Dec 03, 2015
Nimbostratus
The solution article you provided is to modify the ASM cookie and not the application cookie correct? The settings where ASM is modifying the cookie used by the web servers is located in the cookie properties in ASM under Security > Application Security > Headers > Cookie List > Edit Cookie, is that correct?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects