Forum Discussion
DrewW
May 12, 2020Nimbostratus
Header name with no header value
Hi, We had to create a new App Security policy because technical support couldn't tell us why our old one wasn't doing anything after several days of working with them. I am seeing some events ...
Erik_Novak
May 14, 2020Employee
Without some forensic data, it is hard to say based on that single example. The User-Agent string looks legit, but is easily spoofed. I am not an expert on Google's bots, but sending an empty header like that is certainly atypical from what we would consider normal browsing behavior. You could try implementing a bot defense profile, and then allow bots at your discretion. Bot defense will challenge all bots for which you don't specify an exception and prevent them from scraping your application.
- DrewWMay 14, 2020NimbostratusUnfortunately even though we pay F5 a huge sum of money we dont have bot defense.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects