Forum Discussion
Why don't you add the bot as an exception "Mitigation Settings Exceptions" or Whitelist the source IP for the Bot protection:
https://support.f5.com/csp/article/K42323285
Hi!
We have done this both with contains SamsungBrowser/17.0 and added it as exception. We can't whitelist on IP unfortunately. I will however look into the article again if i have missed something.
Best regards,
- Nikoolayy1May 10, 2022MVP
Your Bot Protection is the F5 Advanced WAF (ASM) Bot protection right? You do not use Shape security with F5 Big-IP?
Also from some bugs in the bug tracker you may try stopping the browser verification or Change browser_legit_min_score_drop sys db to be higher value.
https://cdn.f5.com/product/bugtracker/ID693782.html
https://cdn.f5.com/product/bugtracker/ID745531.html
https://cdn.f5.com/product/bugtracker/ID742852.html
As I see many issues with different browsers better open F5 case so they can add this to the Bug tracker for Samsung.
- Fredrik_DanielsMay 10, 2022Altostratus
Yes, WAF Bot protection.
Thing is, i don't understand why its happening when policys also are in transparent mode.- Nikoolayy1May 10, 2022MVP
The Bot protection is seperate from the F5 ASM security policies and they being in Transperant mode does not affect the Bot Protection as the Bot Protection has its own Transperant mode:
https://support.f5.com/csp/article/K42323285
Maybe you need to test if the two bot protection profiles are in transperant mode if the issue will be still there as in Transperant mode the Bot is still marked and maybe the othe Bot Protection is stopping it.
- Fredrik_DanielsMay 10, 2022Altostratus
Thanks Nikoolay for all tips and links! We are having a case opening soon, luckily this browser (at least in our company) is not widely used.
Best regards,- Nikoolayy1May 10, 2022MVP
Yes better see with F5 TAC but it is strange if you are still blocked in everything in transperant mode as it seems as another bug except if for some reason it is the DDOS profile blocking you by device id or the Bot protection has created a dynamic ddos signature or "DoS Attack Mitigation Mode" on the Bot profile to activate DDOS profile: