# iRule - Block part of a query

**URL:** <https://community.f5.com/t/irule-block-part-of-a-query/71184>\
**Category:** Technical Forums\
**Tags:** security, irules\
**Created:** [December 12, 2022, 8:35pm UTC](https://community.f5.com/t/irule-block-part-of-a-query/71184 "2022-12-12T20:35:05Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![PG0581](https://avatars.discourse-cdn.com/v4/letter/p/c37758/32.png) [@PG0581](https://community.f5.com/u/PG0581)\
**Post date:** [December 12, 2022, 8:35pm UTC](https://community.f5.com/t/irule-block-part-of-a-query/71184/1 "2022-12-12T20:35:05Z")

</div>

Using this example URL: [https://abc.com/some-uri.some-extension?func=do-something](https://abc.com/some-uri.some-extension?func=do-something)

How would I go about rejecting any queries containing “do-something”?

This is what I have tried, and haven’t had any luck:

**iRule:**

```tcl
when HTTP_REQUEST {
            if { [class match [string tolower [HTTP::query]] eq data-group-1] }{
            log local0. "Denied query: [IP::client_addr] - [HTTP::query]"
            reject
        }
    }

```

Data-group:

```tcl
ltm data-group internal data-group-1 {
    records {
        do-something { }
    }
    type string
}

```

---

<div class="post-metadata">

**Author:** ![PG0581](https://avatars.discourse-cdn.com/v4/letter/p/c37758/32.png) [@PG0581](https://community.f5.com/u/PG0581)\
**Post date:** [December 12, 2022, 8:57pm UTC](https://community.f5.com/t/irule-block-part-of-a-query/71184/2 "2022-12-12T20:57:26Z")

</div>

I also tried modifying the iRule to use “contains” rather than “eq”, but no luck there either:

```tcl
when HTTP_REQUEST {
            if { [class match [string tolower [HTTP::query]] contains data-group-1] }{
            log local0. "Denied query: [IP::client_addr] - [HTTP::query]"
            reject
        }
    }

```

---

<div class="post-metadata">

**Author:** ![Omar2](https://avatars.discourse-cdn.com/v4/letter/o/ba9def/32.png) [@Omar2](https://community.f5.com/u/Omar2)\
**Post date:** [December 13, 2022, 1:18am UTC](https://community.f5.com/t/irule-block-part-of-a-query/71184/3 "2022-12-13T01:18:21Z")

</div>

Hello,

The below simple I-rule do this function and tested in a LAB:

when HTTP\_REQUEST {  
if {[HTTP::uri] contains “do-something”}{  
reject  
}  
}

---

<div class="post-metadata">

**Author:** ![CA\_Valli](https://avatars.discourse-cdn.com/v4/letter/c/9dc877/32.png) [@CA\_Valli](https://community.f5.com/u/CA_Valli)\
**Post date:** [December 13, 2022, 8:22am UTC](https://community.f5.com/t/irule-block-part-of-a-query/71184/4 "2022-12-13T08:22:22Z")

</div>

Hello&nbsp; @PG0581 &nbsp;,&nbsp;  
this code should work, and it’s exactly how I would build the iRule too.

Any reason why you’re using “string tolower”? Remember that in this case, your datagroup should be all lowercase characters in order to match.

In my lab, this code is working indeed

 ![CA_Valli_0-1670919730064.png](https://d20hrnpixdzcsd.cloudfront.net/original/3X/5/0/50f87ff20bc8ba87388e483bcea1d3a5a4ff9901.png)

I would check profiles on your VS .. you need HTTP profile to parse [HTTP::query] info, and if this HTTPS traffic you also need a clientSSL profile in order to see unencrypted data.

---

<div class="post-metadata">

**Author:** ![Kai\_Wilke](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/kai_wilke/32/24646_2.png) [@Kai\_Wilke](https://community.f5.com/u/Kai_Wilke)\
**Post date:** [December 13, 2022, 9:15am UTC](https://community.f5.com/t/irule-block-part-of-a-query/71184/5 "2022-12-13T09:15:49Z")

</div>

Hi PG0581,

you may check the modified iRule below…

```tcl
when HTTP_REQUEST {
		if { [class match -- [URI::query [HTTP::uri -normalized] "func"] equals data-group-1] } then {
		log local0. "Denied query: [IP::client_addr] - param func=[URI::query [HTTP::uri -normalized] "func"]"
		HTTP::respond 403 content "Access Denied" "Content-Type" "text/html"
	}
}

```

It applies HTTP::uri -nomalization to the request URI, then extracts the URI parameter “func” and then checks the value based on your Data-Group. If the func param is listed in the blacklist, it sends a HTTP 403 Access Denied to the client (slightly better than using a TCP reject).

Cheers, Kai

---

<div class="post-metadata">

**Author:** ![PG0581](https://avatars.discourse-cdn.com/v4/letter/p/c37758/32.png) [@PG0581](https://community.f5.com/u/PG0581)\
**Post date:** [December 15, 2022, 1:46pm UTC](https://community.f5.com/t/irule-block-part-of-a-query/71184/6 "2022-12-15T13:46:06Z")

</div>

Hi&nbsp; @CA_Valli &nbsp;,

Thanks for testing this. I have typically always used “string tolower”, but what I did not realize or had not noticed is the string in the data-group needs to be lowercase as well. Makes total sense! The string in my data-group is not all in lowercase, so I will fix that.

---

<div class="post-metadata">

**Author:** ![PG0581](https://avatars.discourse-cdn.com/v4/letter/p/c37758/32.png) [@PG0581](https://community.f5.com/u/PG0581)\
**Post date:** [December 15, 2022, 1:51pm UTC](https://community.f5.com/t/irule-block-part-of-a-query/71184/7 "2022-12-15T13:51:18Z")

</div>

Thanks for testing this&nbsp; @Omar2 &nbsp;! I will add this to my notes as another solution.

---

<div class="post-metadata">

**Author:** ![PG0581](https://avatars.discourse-cdn.com/v4/letter/p/c37758/32.png) [@PG0581](https://community.f5.com/u/PG0581)\
**Post date:** [December 15, 2022, 1:52pm UTC](https://community.f5.com/t/irule-block-part-of-a-query/71184/8 "2022-12-15T13:52:10Z")

</div>

Thanks for your feedback&nbsp; @Kai_Wilke &nbsp;. Interesting way of writing the iRule, and thanks for the tip on sending the 403 back 🙂 I will add this to my notes!

---

<div class="post-metadata">

**Author:** ![CA\_Valli](https://avatars.discourse-cdn.com/v4/letter/c/9dc877/32.png) [@CA\_Valli](https://community.f5.com/u/CA_Valli)\
**Post date:** [December 15, 2022, 1:54pm UTC](https://community.f5.com/t/irule-block-part-of-a-query/71184/9 "2022-12-15T13:54:06Z")

</div>

Happy to help!  
I typically use that syntax if I need to normalize some data, but with URI’s /login and /LOGIN would be two different pages and you might have unexpected matches..

---

<div class="post-metadata">

**Author:** ![PG0581](https://avatars.discourse-cdn.com/v4/letter/p/c37758/32.png) [@PG0581](https://community.f5.com/u/PG0581)\
**Post date:** [December 15, 2022, 1:59pm UTC](https://community.f5.com/t/irule-block-part-of-a-query/71184/10 "2022-12-15T13:59:05Z")

</div>

Noted! Thanks again!
