Forum Discussion

Kenny_Aldrin's avatar
Kenny_Aldrin
Icon for Nimbostratus rankNimbostratus
Apr 28, 2017

Ignore certain cookies for ASM

Hi All,

 

I am having a problem on our LTM/ASM (ver 11.5.1) box. We use cookie persistence configured on the virtual server. Lately we had to encrypt the persistence cookie for added security. The result is, sometimes the encryption causes the value of the cookie to be some weird characters. And our environment requires that all headers have to meet certain character standard.

 

My question, is there a way to ignore the persistence cookie (or cookie characters to be specific) on ASM? I know we can ignore the Attack Signatures for the cookie, but we need certain characters to be blocked on Headers in general, but ignored in this particular cookie.

 

Appreciate any advice,

 

Thanks,

 

Kenny

 

2 Replies