Forum Discussion
illegal cookie length: ASM violation
HI ASM experts, I am seeing traffic getting blocked due to the "Illegal cookie length violation" . System configured: 8192 bytes, received 8452. I am running 11.5.1 HF7. I tried to increase the cookie length by going to the policy and selecting advanced, BUT it gave me an error that the max allowed is 8192 bytes. What is the work around for this? This seems to be a legit GET request.
16 Replies
Hi,
8192 bytes is the default length, not the max allowed in general.
I will try it on my lab and give you a feedback
- In fact, that's true. 8192 bytes is the maximum length you can define for header and cookies. This is a limit that include name+value. You can change this setting by Any if you have headers that exceed this max length
- Yann_Desmarest_
Nacreous
Hi,
8192 bytes is the default length, not the max allowed in general.
I will try it on my lab and give you a feedback
- Yann_Desmarest_
Nacreous
In fact, that's true. 8192 bytes is the maximum length you can define for header and cookies. This is a limit that include name+value. You can change this setting by Any if you have headers that exceed this max length
- Hannes_Rapp_162
Nacreous
8192 Is indeed the maximum and I think you only have 2 workarounds - disable the violation, or write a custom iRule. Disabling the violation itself would probably make the most sense here.
Go to policy blocking settings, and un-tick the 'learn/alarm/block' boxes under
violation. Save and apply changes.Illegal cookie length- MSZ
Nimbostratus
What about 2048 bytes
- Hannes_Rapp_162
Nacreous
@MSZ - Can't understand the question
- MSZ
Nimbostratus
when I created the ASM policy longtime back I didn't notice the value of Max. cookie header length (It comes on Policy properties page). As per documentation it is any by default. But in my case I am able to see the value like 2048. I want to know how this value comes and where ?
- Hannes_Rapp
Nimbostratus
8192 Is indeed the maximum and I think you only have 2 workarounds - disable the violation, or write a custom iRule. Disabling the violation itself would probably make the most sense here.
Go to policy blocking settings, and un-tick the 'learn/alarm/block' boxes under
violation. Save and apply changes.Illegal cookie length- MSZ
Nimbostratus
What about 2048 bytes
- Hannes_Rapp
Nimbostratus
@MSZ - Can't understand the question
- MSZ
Nimbostratus
when I created the ASM policy longtime back I didn't notice the value of Max. cookie header length (It comes on Policy properties page). As per documentation it is any by default. But in my case I am able to see the value like 2048. I want to know how this value comes and where ?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com