having a problem with F5 WAAP while im trying to take a service behind WAAP.
here is my architecture.
i have a Customer Edge on my network and this customer edge is on same subnet with my private application.
XC can connect my CE successfully there is no problem with that, and i have created HTTP LB and origin servers.
also i provide my custom certificate and point my CNAME to F5 XC given cname address.
but when im trying to connect my application im having this error;
The requested URL was rejected. Please consult with your administrator.
Your support ID is XXXXXXXXXXXXXXXXXXXXX
You have not provided a lot of info.
Is the origin pool health monitor http/htttps and is it up ?
Have you seen if you can connect to the server when you remove the WAF and service policies under the LB?
In the logs investigate if you see any errors like TLS errors as maybe you have not enable tls under the origin or the tls level need to be set to medium and low and to not check the server certificates under the origin. Also in the http logs (review the security and performance logs under the Dashboards in XC) you can see the real server response code (upstream response) but better remove the WAF and Service policies as I said.
Other than that F5 XC by default overwites the Host header value when sending traffic to the origin servers and this can be dissabled under the route objects.
You will need to do some investigation on your own I suggest maybe taking the F5 training in the link below if you are going to support this product:
thank you for your kind responses, here is the detailed log im seeing,
As I mentioned better go through the F5 XC training for you to be able to narrow down the issue and then maybe to provide a more detailed info in the forum when the issue is complex and you can't solve it. The error for me suggests that maybe the issue is with your Customer Edge (CE) in some way as probably your Load Balancer or origin pool is on the CE not on the XC Global Cloud Regional Edge RE.
This message cluster_not_found could be related to your CE cluster of 3 nodes but why it is not found when you mentioned that the CE is ok I can't tell.