Forum Discussion
F5 ASM | Bot Signature
Hi tpimpao,
seems you are right. Testing with 16.1 and 17.1 the "Advanced Mode" only allows the following tags:
- headercontent (cannot be used without useragentonly)
- uricontent
Other options and modifiers (as documented in https://techdocs.f5.com/en-us/bigip-14-1-0/big-ip-asm-attack-and-bot-signatures-14-1-0/signature-syntax.html) do not work.
Please read also: BIG-IP Application Security Manager: Attack and Bot Signatures > Writing Custom Bot Signatures
You could write an iRule, that will check for multiple headers or others attributes of the HTTP request and then block the request.
KR,
Daniel
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com