Forum Discussion
Response Headers Allowed
Hi All,
I am studying F5 Ltm and want to know, What is the use of "Response Headers Allowed"option in HTTP profile?
Rgds Mukul
2 Replies
- Kevin_Stewart
Employee
It is a literal filter on the header names that are allowed to pass to the client in the HTTP response. Some headers, particularly those that affect functionality of an application like Set-Cookie and Content-Type, are not blocked by this HTTP profile option. Others, like Server and Date, can be blocked. It's also a whitelist option if a value is specified. If the field is left blank, all headers are allowed through. If header names are specified, ONLY those headers will pass (barring the functional headers). The text block takes multiple header names, space delimited.
- Anthony_Cheng_1
Nimbostratus
It can be useful in troubleshooting where you need to do a HTTP trace and wanted to see only specific headers, e.g. You setup a test HTTP Profile with specific option for "Response Headers Allowed".
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com