Forum Discussion
MSZ
Nimbostratus
May 17, 2016Status Code 500
WAF is blocking request due to 500 code.
(illegal HTTP status in Response)
Why WAF is blocked requests and how 500 code comes?
When request is blocked by WAF means it did not cross the WAF?...
Yann_Desmarest
Cirrus
May 17, 2016Hello,
500 status code indicates that you web server had an error for processing the request.
ASM offload those response by default to avoid guessing issues. We don't want that the full error stack is displayed on the client browser. Information provided by servers sometimes help attackers to target an attack.
You can disable 500 status code offloading by removing this status code from the list of unallowed status code in the main pagz of your security policy
- MSZMay 17, 2016
Nimbostratus
If request is blocked at WAF then how a response comes from server? Confusing - Yann_DesmarestMay 17, 2016
Cirrus
Hi, the setting we are talking about is one of them that do not block the request and just change the response because asm receive a 500 status code from the backend - Yann_DesmarestMay 17, 2016
Cirrus
O'm talking about illegal HTTP status in Response violation that you grap in your asm event logs
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects