Forum Discussion

Mukul_Joshi_142's avatar
Mukul_Joshi_142
Icon for Nimbostratus rankNimbostratus
Jan 29, 2014

Response Headers Allowed

Hi All,

 

I am studying F5 Ltm and want to know, What is the use of "Response Headers Allowed"option in HTTP profile?

 

Rgds Mukul

 

2 Replies

  • It is a literal filter on the header names that are allowed to pass to the client in the HTTP response. Some headers, particularly those that affect functionality of an application like Set-Cookie and Content-Type, are not blocked by this HTTP profile option. Others, like Server and Date, can be blocked. It's also a whitelist option if a value is specified. If the field is left blank, all headers are allowed through. If header names are specified, ONLY those headers will pass (barring the functional headers). The text block takes multiple header names, space delimited.

     

  • It can be useful in troubleshooting where you need to do a HTTP trace and wanted to see only specific headers, e.g. You setup a test HTTP Profile with specific option for "Response Headers Allowed".