Forum Discussion
Status Code 500
WAF is blocking request due to 500 code. (illegal HTTP status in Response)
Why WAF is blocked requests and how 500 code comes?
When request is blocked by WAF means it did not cross the WAF? As I know that 500 code is from Application crush.
Which thing in user request gets block message.
8 Replies
Hello,
500 status code indicates that you web server had an error for processing the request.
ASM offload those response by default to avoid guessing issues. We don't want that the full error stack is displayed on the client browser. Information provided by servers sometimes help attackers to target an attack.
You can disable 500 status code offloading by removing this status code from the list of unallowed status code in the main pagz of your security policy
- MSZ
Nimbostratus
If request is blocked at WAF then how a response comes from server? Confusing - Hi, the setting we are talking about is one of them that do not block the request and just change the response because asm receive a 500 status code from the backend
- O'm talking about illegal HTTP status in Response violation that you grap in your asm event logs
- Yann_Desmarest_
Nacreous
Hello,
500 status code indicates that you web server had an error for processing the request.
ASM offload those response by default to avoid guessing issues. We don't want that the full error stack is displayed on the client browser. Information provided by servers sometimes help attackers to target an attack.
You can disable 500 status code offloading by removing this status code from the list of unallowed status code in the main pagz of your security policy
- MSZ
Nimbostratus
If request is blocked at WAF then how a response comes from server? Confusing - Yann_Desmarest_
Nacreous
Hi, the setting we are talking about is one of them that do not block the request and just change the response because asm receive a 500 status code from the backend - Yann_Desmarest_
Nacreous
O'm talking about illegal HTTP status in Response violation that you grap in your asm event logs
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com