For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

kaoutar's avatar
kaoutar
Icon for Cirrus rankCirrus
Oct 23, 2020

Wildcard URL with "dot" allowed confused with a file type

Hello evryone

 

I configuered a wildcard URL (/x/y/*) in my ASM policy with the "." as an allowed meta character, but all the requests /x/y/1245.452 for example are blocked by violation illegal file type, does anyone know how to fix this issue ?

 

Thanks in advance

1 Reply

  • There's really only two solutions:

    (1) Accept the filetype and do nothing

    (2) create a wildcard file type which will accept all non-explicit filetypes including no_ext.

      no_ext filetypes are those urls with no periods that works in conjunction with wildcards

      Note that the burden of enforcement will shift to url matching.

      violation will not be a bad filetype, but rather an unknown url

     

    There is a feature request to prevent this behavior but it hasn't been added to any F5 software yet ID400017.