Forum Discussion
Login failed because of invalid referer header
Hi Srj73,
I tested using a different proxy instead of AzureGW.
- There was no problem with the default settings.
- When I changed the referer header in proxy, I got the same error.
err httpd[28597]: [f5_auth_cookie:error] [pid 28597] [client 172.22.101.205:41795] Login failed because of invalid referer header., referer: https://172.22.199.1/tmui/logmein.html?
- When I deleted the referer header in proxy, I got the below error.
err httpd[29765]: [f5_auth_cookie:error] [pid 29765] [client 172.22.101.205:34778] Login is not permitted without a valid referer header or forwarded header when sys db variable systemauth.permitloginwithoutheaders is disabled.
The following method can be applied as a workaround.
- Remove Referer header on AzureGW.
- Change db parameter.
tmsh modify sys db systemauth.permitloginwithoutheaders value enable
- Save config and restart httpd service.
tmsh save sys config
tmsh restart sys service httpd
- Srj73May 29, 2023Altostratus
Now, I have done few change
1. AppGW (port:https [earlier http on 8443]) > F5 (port:https[earlier https on 8443]) (This step is different and New Today)
2. Enabled systemauth.permitloginwithoutheaders (yesterday i enabled it during troubleshooting)
3. deleted the Refereal Header, (yesterday, i tried this step)
then it started giving below error
"May 29 17:02:31 localhost.localdomain err httpd[17412]: [auth_pam:error] [pid 17412] [client 10.21.0.4:19958] AUTHCACHE Error processing cookie VKJ4PU96LUgjepNSy1L6HUVOWJNWwr0v7s3C69RO - Cookie impersonation detected from client IP 10.21.0.4 to client IP 10.21.0.6"
4. Then as per article https://my.f5.com/manage/s/article/K13048 i done the step
5. Now, I am able to access the device
- Leslie_HubertusJun 08, 2023Ret. Employee
So everything works properly, now?
- Srj73Jun 19, 2023Altostratus
yes..
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com