Forum Discussion

Paul_Brand_2026's avatar
Paul_Brand_2026
Icon for Nimbostratus rankNimbostratus
Sep 01, 2017

ASM and ADFS

Hi

 

I am deploying LTM for balancing ADFS. As ADFS is using https customer has asked if ASM inspection is possible and if it would add any value.

 

Is anybody able to help answer to this?

 

Thanks in advance

 

1 Reply

  • nathe's avatar
    nathe
    Icon for Cirrocumulus rankCirrocumulus

    Paul, I haven't done this myself, but my general opinion is if a http(s) service is published on the internet then a WAF will, in most cases, offer some protection and I would recommend it. This would be to prevent against known http rfc violations and general attacks, like xss.

     

    A quick search on ADFS vulnerabilities returned this CVE which is a XSS vulnerability. So, a WAF in a purely negative model of security would help.

     

    Hope this helps,

     

    N