Forum Discussion
Rodolphe_AUBINE
Nimbostratus
Jun 24, 2010How to bypass (header Referer) from policies controls
Hi,
Some clients come to our websites with an "Header : Referer" wich is rejected by several signatures from ASM.
How can I disable ASM checks on this specific Header ?
Is it...
hoolio
Cirrostratus
Jun 24, 2010Hi Rodolphe,
Unfortunately, ASM doesn't provide the ability to customize the policy enforcement by header name/value like you can with parameters. This would be a very useful feature as the Referer header often has many metacharacters I'd prefer not to allow for all headers and strings which match attack sigs that I wouldn't want to have to disable in the policy.
I've just ended up disabling any of the attack sigs which trigger false positives for the HTTP headers. I suppose you could try to do something clever with an iRule to sanitize the Referer header, but that might break the application.
You could open a case with F5 Support and ask them to consider adding a feature which would allow customization of the policy enforcement by header name.
Aaron
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects