Technical Forum
Ask questions. Discover Answers.
cancel
Showing results for 
Search instead for 
Did you mean: 

AWAF block a list of parameters values

Ben_D
Nimbostratus
Nimbostratus

Hi, everyone.

I would like to know if it is possible to block a list of parameters values with f5 awaf.

I know it's possible with irule and datagroups. But the irule isn't safe due to encoding characters values, that is not read by irule.

 

Thanks for your help.

1 REPLY 1

crodriguez
Legacy Employee
Legacy Employee

Rather than block disallowed values, if you know what the allowed values are, you can create a static content value parameter that includes those values. Any other values would be disallowed.

 

If all you know are the values that are NOT allowed, you should be able to create a custom attack signature and attack signature set that includes those disallowed value strings. You can then add the parameter to the policy (manually or via learning), and then add the attack signature set to that specific parameter.