Forum Discussion
ptate_72056
Nimbostratus
Jan 23, 2009Persistence cookies and security
Hi Everyone,
We've recently had a security audit reveal that the BigIP persistence cookie contains the IP address and the port of the node the user connected to.
I can see why this is required from a BigIP point of view but is there any way of securing this information, bar not using cookie-based persistence.
Many thanks in advance,
Phill
- hoolio
Cirrostratus
Hi Phil, - Skuba_85554
Nimbostratus
hi hoolio - Deb_Allen_18Historic F5 AccountThe cookie data is encrypted and decrypted by the LTM only using the specified key. The client, since it does not have the key, cannot decrypt the cookie, so any data within it is not readable by the client.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects