Forum Discussion
Facing problem with Modified domain cookies
BIG-IP ASM cookies are session based and do not get written to disk. When the user is connecting to the application using incognito mode, there is no existing cookie so the violation is not triggered. See K5907: BIG-IP ASM violation: Modified domain cookie
The most common reason the cookie changes is that the client makes a request to another app on the same domain not passing through the same ASM policy which modifies the cookie. Another common cause for the violation is that the ASM cookie is set with a different expiry than the app's cookie. If you can reproduce the issue, try using your browser's development tools to view the cookies in use for the application and monitor changes to the cookie between ASM sessions.
- AantatJan 13, 2023Cirrus
Hi, so I think I find the reason of my problem. Violation is triggered when user uses my app via example.com after www.example.com. Is there any suggestion on that? Should I do redirect from www to my example.com?
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com