Forum Discussion
Issue with AWAF Blocking Compressed Files Despite Wildcard Inclusion
Hello I have been working many years with F5 and the WAF max can block file executables as shown in Configuring the BIG-IP ASM system to block file uploads containing binary executable content . One way with regex as shown in WAF - Allow uploads of only files with certain extensions and block all other file uploads | DevCentral is to match the extensions in the parameter value but AWAF is not meant for this as better use ICAP and send traffic to a malware and content detection system that will do more than just checking extensions as this is no real security at all but will actually analyze the file.
Metadefender can do advanced file type detection for example:
See:
F5 ICAP over SSL/TLS (Secure ICAP) with F5 ASM/AWAF Antivirus Protection feature | DevCentral
Integrating OPSWAT MetaDefender with F5 Advanced WAF & BIG-IP ASM | DevCentral
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
