Forum Discussion

Amr_Esmat_24704's avatar
Amr_Esmat_24704
Icon for Nimbostratus rankNimbostratus
Aug 20, 2018

ASM policy doesn't block metacharacters in paramters name and value

I have ASM policy in blocking mode for a VS rules are as below:

 

  1. parameters allowed wildcard *, Value or Name Meta characters are now allowed only space and : allowed in value not parameter name
  2. under Application Security : Blocking : Settings Illegal meta character in parameter name and Illegal meta character in value both are blocking
  3. url allowed wildcard /page1*

when I test url parameters to check if the policy works correctly:

 

  1. /page1?a=

6 Replies

  • No violations triggered, I also changed settings under blocking to alarm or block but the request passes with no violation or block triggered

     

    Version BIG-IP 11.6.3 Build 0.0.3 Final

     

  • Violations against a parameter in staging will not trigger blocking behavior - also true for file types and URLs. Take the parameter out of staging, re-run the test and I would not be surprised if you see blocking behavior.