Forum Discussion
F5 is not blocking Cross Site Script attack
Dear Sam,
I had two BIG-IP box, one LTM box, and one ASM box. Data flow of my application was come from LTM box to ASM box, ASM do inspection, and send back to LTM box.
I had no iRules/LTM policies/HTTP Class that redirect data traffic and make it not going through ASM. The only iRules I used on LTM box is for redirecting traffic from http to https.
If there is any iRules/LTM policies/HTTP Class that redirect traffic, so all url request should be not logged on ASM, and ASM can't do manual traffic learning. But on my case, ASM logged all traffic except this XSS alert() request.
Thanks..
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com