Mar 27, 2026 - For details about updated CVE-2025-53521 (BIG-IP APM vulnerability), refer to K000156741.

Forum Discussion

RKC_260787's avatar
RKC_260787
Icon for Nimbostratus rankNimbostratus
Jul 23, 2018

HTTP Referer headers

I have a requirement to check HTTP Referer headers and restrict it to base URL and anything else should be denied .

 

Example -- URL -- https://123test123.com Referer Header should be only https://123test123.com/* anything else denied

 

Can you suggest a iRule

 

1 Reply

  • when HTTP_REQUEST {
        set referer [string tolower [HTTP::header value "Referer"]]
        
         Reject if Referer is not blank and does not start with https://123test123.com/
        if {($referer != "") && !($referer starts_with "https://123test123.com/")} {
            log local0.info "Rejecting request to [HTTP::uri] with Referer $referer"
            reject
        }
    }