For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

ASCapi's avatar
ASCapi
Icon for Cirrus rankCirrus
Oct 24, 2025
Solved

LTM issue Openning new web browser tab

ello everyone , 

I got LTM issue I think But I am not still able to identify the right parameter to set on http header.
the issue is, from ITMS when I  try to edit a comment or task. I got new tab whereas I should got possibilité to edit the item. 

I am though I could be the referer setting but which param from http head. 
Anyone can support or  give some track ? 

Thanks for you feeback

  • ASCapi's avatar
    ASCapi
    Oct 31, 2025

    Hi, It's almost resolved

    Finaly I saw  the issue side is on WAF, CSRF Protection. I deside for now to disable the feature and working in test environment. 

    Hope to re-enable CSRF after fixed the issue, in LAB

     

14 Replies

  • Hello

    You describe the expected behaviour but I don't understand what is the current behaviour.

    Have you checked browser developer tools?

    • ASCapi's avatar
      ASCapi
      Icon for Cirrus rankCirrus

      Hi Injeyan_Kostas​ 
      I do but I am still a beginner on systems. 

      Currently I do not identify the http header.

      Thank you for the suggestion
      I will give feedback

      • Injeyan_Kostas's avatar
        Injeyan_Kostas
        Icon for Nacreous rankNacreous

        What http header are you talking about?

        I still don't understand what issue do you have 

        You say that you get a new tab where you should be able to edit the item. But what is the issue you don't get a new tab? You get a new tab but you cannot edit? Something else?

  • Hello, I hope you have enabled the required layer 7 profile(eg ,https)

    Under your VS’s HTTP profile:

    “Insert X-Forwarded-For” → should be enabled if the app expects client IP.

    “Rewrite Redirects” → may need to be set to Matching or All if app uses redirects

    “Fallback host” / “Redirect rewrite” – ensure not rewriting to IP or another domain.

    Also confirm:

    “Header Erase” or “Header Insert” fields aren’t removing or renaming “Referer” or “Origin”.

    • ASCapi's avatar
      ASCapi
      Icon for Cirrus rankCirrus

      Hi Aswin_mk​ 
       
      I will check it all et let you. Some options weren't enabled on http profil. I changed them

       

      Cdlt