Forum Discussion

sachin_80710's avatar
sachin_80710
Icon for Nimbostratus rankNimbostratus
Nov 04, 2015

F5 ASM how to ignore URL query string parameter learning

Hi Team,

 

I'm facing issue with URL query string parameter learning. As per my knowledge any thing after '?' in URL is considered as query string parameter.

 

Sometimes query string parameter are not properly separated so ASM is not properly learning Parameter name like sometime club name of multiple parameter name as single parameter name. To ignore learning of query string parameter under security policy Security > Application Security > Security Policies Handle Path Parameters is set to ignore, But i can see ASM is learning query string parameter. Please suggest how to ignore query string parameter.

 

Thanks Sachin

 

4 Replies

  • In your Security Policy (still in learning mode), do you have Wildcards Tightening enabled for parameters? If yes, that's the tickbox you should unselect.

     

    • sachin_80710's avatar
      sachin_80710
      Icon for Nimbostratus rankNimbostratus
      Thanks Hannes, Security policy is in learning mode. Will try disabling wildcards tightening for parameter. Thanks, Sachin
  • In your Security Policy (still in learning mode), do you have Wildcards Tightening enabled for parameters? If yes, that's the tickbox you should unselect.

     

    • sachin_80710's avatar
      sachin_80710
      Icon for Nimbostratus rankNimbostratus
      Thanks Hannes, Security policy is in learning mode. Will try disabling wildcards tightening for parameter. Thanks, Sachin