For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Wasfi_182818's avatar
Wasfi_182818
Icon for Altostratus rankAltostratus
Jun 06, 2016

Host Header having an IP address value

Hi;

 

My understanding is that the ASM by default disallows a HTTP request with a host header value that is not an FQDN. Someone however has assured me that this is not the case.

 

Kindly Wasfi

 

1 Reply

  • Hi,

     

    You can activate this feature on ASM with "Host header contains IP address" option in "HTTP Protocol Compliance Failed" section under Blocking menu.

     

    This settings is not necessarly activated by default, it depends on which template you are using. But you can definetly activate it after setting up you security policy wizard.