HTTP Status Code 403 seems to be a reasonable response by a web application unwilling to fulfuil a request. So, I'm at loss to understand why F5 excluded it from default allowed HTTP Status Codes in AWAF/ASM ASP - can anyone enlighted?
Solved! Go to Solution.
Not sure which version of ASM7WAF you are running. I haven't face such issue.
Capture form above link
The default BIG-IP ASM configuration allows by default response codes 200 through 399 and 400, 401, 403, 404, 407, 417, 500 and 503. All other HTTP response codes are blocked by the BIG-IP ASM
I had to do a double take.., but no... in my v16.1.0, "403" is excluded from default (for Fundamental template).
Also, in your hyperlink's hyperlink K7922: Overview of BIG-IP ASM HTTP response code filtering, 403 is also excluded for "BIG-IP ASM 11.3.0 and later"