# Unable to mask XML parameter

**URL:** <https://community.f5.com/t/unable-to-mask-xml-parameter/72800>\
**Category:** Technical Forums\
**Tags:** security, application-delivery\
**Created:** [August 1, 2023, 11:58am UTC](https://community.f5.com/t/unable-to-mask-xml-parameter/72800 "2023-08-01T11:58:06Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aantat](https://avatars.discourse-cdn.com/v4/letter/a/c2a13f/32.png) [@Aantat](https://community.f5.com/u/Aantat)\
**Post date:** [August 1, 2023, 11:58am UTC](https://community.f5.com/t/unable-to-mask-xml-parameter/72800/1 "2023-08-01T11:58:06Z")

</div>

Hello F5 experts,

I was configuring AWF policy and faced a problem with masking value of XML parameter.&nbsp;but without success.

I’ve imported [XML scheme](https://my.f5.com/manage/s/article/K33285226). I’ve configured Value Masking&nbsp;according to the [documentation](https://my.f5.com/manage/s/article/K52154401#xml). I’ve tried to configure it as a [Sensetive Parameter,](https://techdocs.f5.com/kb/en-us/products/big-ip_asm/manuals/product/asm-implementations-11-5-0/29.html) but without success.

What am I missing? What should I set up? Where am I making a mistake?

I will be glad for any help.

---

<div class="post-metadata">

**Author:** ![Mostafa\_Elsayed](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/mostafa_elsayed/32/18702_2.png) [@Mostafa\_Elsayed](https://community.f5.com/u/Mostafa_Elsayed)\
**Post date:** [August 1, 2023, 2:18pm UTC](https://community.f5.com/t/unable-to-mask-xml-parameter/72800/2 "2023-08-01T14:18:00Z")

</div>

Hi&nbsp; @Aantat &nbsp;,

I faced same issue with AJAX profile, and one missed thing here is attaching XML profile you create in (Wildcard) HTTPS url.

You can follow below KB ( **K39482497** ) and share result with us.

> **[myF5](https://my.f5.com/manage/s/article/K39482497)**

---

<div class="post-metadata">

**Author:** ![Aantat](https://avatars.discourse-cdn.com/v4/letter/a/c2a13f/32.png) [@Aantat](https://community.f5.com/u/Aantat)\
**Post date:** [August 2, 2023, 1:16pm UTC](https://community.f5.com/t/unable-to-mask-xml-parameter/72800/3 "2023-08-02T13:16:06Z")

</div>

I followed that KB but I’m still facing same issue. It’s not working

---

<div class="post-metadata">

**Author:** ![Aantat](https://avatars.discourse-cdn.com/v4/letter/a/c2a13f/32.png) [@Aantat](https://community.f5.com/u/Aantat)\
**Post date:** [August 2, 2023, 1:28pm UTC](https://community.f5.com/t/unable-to-mask-xml-parameter/72800/4 "2023-08-02T13:28:33Z")

</div>

Hello experts,

I’m still facing the issue with masking parameter value. I’ve tried lot’s of combinations in Header-Based Content Profile, but no success.

Could the problem be that the value of the Content-Type is the ‘application’ and not the ‘xml’?

How can I validate my XML scheme?&nbsp;Could the problem is wrong XML scheme?

Added some screenshots with requests and example of configurations.

 ![ar2.PNG](https://d20hrnpixdzcsd.cloudfront.net/original/2X/0/0cb6674ce7de19e9bbb330f36d3a9c6a3b002667.jpeg)

 ![ar1.PNG](https://d20hrnpixdzcsd.cloudfront.net/original/1X/991a4f16c89fc4b2a742d0ebb4409936bb8a56bf.jpeg)

---

<div class="post-metadata">

**Author:** ![Ismael\_Goncalves](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/ismael_goncalves/32/12650_2.png) [@Ismael\_Goncalves](https://community.f5.com/u/Ismael_Goncalves)\
**Post date:** [August 8, 2023, 4:55pm UTC](https://community.f5.com/t/unable-to-mask-xml-parameter/72800/5 "2023-08-08T16:55:22Z")

</div>

@Aantat &nbsp;“Could the problem be that the value of the Content-Type is the ‘application’ and not the ‘xml’?”

That’s correct. Your Content-Type is ‘application/x-www-form-urlencoded’ which will not match the \*xml\* Content-Type expected to trigger the XML parsing and XMl profile assisngment. Hence, the data won’t be masked.

If all the requests to this URL are expected to be XML even if the request does not present the correct Content-Type, you can configure content-type ‘\*form\*’ and treat it as an XML.

---

<div class="post-metadata">

**Author:** ![zamroni777](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/zamroni777/32/1473_2.png) [@zamroni777](https://community.f5.com/u/zamroni777)\
**Post date:** [June 24, 2024, 5:16pm UTC](https://community.f5.com/t/unable-to-mask-xml-parameter/72800/6 "2024-06-24T17:16:21Z")

</div>

ensure that the xsd is correct.

you can try this website

> **[Free Online XML Validator (XSD)](https://www.liquid-technologies.com/online-xsd-validator)**
>
> Validates an XML document using an XSD schema.
