Forum Discussion
Ignore certain cookies for ASM
Hi All,
I am having a problem on our LTM/ASM (ver 11.5.1) box. We use cookie persistence configured on the virtual server. Lately we had to encrypt the persistence cookie for added security. The result is, sometimes the encryption causes the value of the cookie to be some weird characters. And our environment requires that all headers have to meet certain character standard.
My question, is there a way to ignore the persistence cookie (or cookie characters to be specific) on ASM? I know we can ignore the Attack Signatures for the cookie, but we need certain characters to be blocked on Headers in general, but ignored in this particular cookie.
Appreciate any advice,
Thanks,
Kenny
- Tikka_Nagi_1315Historic F5 Account
You can accomplish the using Header-Based Content Profiles https://support.f5.com/kb/en-us/products/big-ip_asm/manuals/product/asm-implementations-11-5-0/31.html
Under the "Header-Based Content Profiles", there are 3 options
Request Header Name ---> Set a Cookie header. Request Header Value ---> Set a Cookie value. Request Body Handling ---> Set as "Do nothing"
This will have to be configured per-url.
- Kenny_Aldrin
Nimbostratus
Thanks Tikka!
I've got the same answer from F5 support. Case closed
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com