Forum Discussion
DrewW
Nimbostratus
May 12, 2020Header name with no header value
Hi, We had to create a new App Security policy because technical support couldn't tell us why our old one wasn't doing anything after several days of working with them. I am seeing some events ...
Erik_Novak
Employee
May 14, 2020Without some forensic data, it is hard to say based on that single example. The User-Agent string looks legit, but is easily spoofed. I am not an expert on Google's bots, but sending an empty header like that is certainly atypical from what we would consider normal browsing behavior. You could try implementing a bot defense profile, and then allow bots at your discretion. Bot defense will challenge all bots for which you don't specify an exception and prevent them from scraping your application.
DrewW
Nimbostratus
May 14, 2020Unfortunately even though we pay F5 a huge sum of money we dont have bot defense.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
