Forum Discussion
Mohammed_M_Irfa
Nimbostratus
Aug 16, 2018Security Parameters: Need to be apply to make secure solutions
Hi,
We have BIG-IP LTM+ASM in HA, 13.1.0v latest version is running.
Standard type Virtual server is configured, TCP and HTTP profile is enabled.
SNAT Pool List is enalbed.
ASM Security Pol...
Aug 16, 2018
Hi,
- Which cookie does not contain the "secure" attribute? Your BIG-IP persistence cookie? If so you should enable it on the cookie persistence profile. If it is the application cookie you should rewrite that cookie (with an irule) to insert the "secure" attribute.
- Is this for the webserver or for your BIG-IP persistence cookie? (if it is your BIG-IP persistence cookie, enable encryption on the cookie (I think you should alway's encrypt your BIG-IP persistence cookie))
- Enable HTTP Strict transport security on your BIG-IP HTTP Profile (or is there another header your security team want's to insert?)
- Did you enable the directory listing attack signatures in your ASM policy?
Cheers,
Kees
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
