I would like to know if it is possible to block a list of parameters values with f5 awaf.
I know it's possible with irule and datagroups. But the irule isn't safe due to encoding characters values, that is not read by irule.
Thanks for your help.
Rather than block disallowed values, if you know what the allowed values are, you can create a static content value parameter that includes those values. Any other values would be disallowed.
If all you know are the values that are NOT allowed, you should be able to create a custom attack signature and attack signature set that includes those disallowed value strings. You can then add the parameter to the policy (manually or via learning), and then add the attack signature set to that specific parameter.