Bug ID 562164: Maintain a list of excluded headers and URLs for client side challenges

Last Modified: Apr 28, 2025

Affected Product(s):
BIG-IP ASM(all modules)

Fixed In:
12.1.0

Opened: Dec 09, 2015

Severity: 3-Major

Symptoms

The client side challenge (as PBD or as a mitigation), on ASM or on DosL7, causes a page not to load or load with error.

Impact

A page fails to load.

Conditions

A functionality that involves the client side mitigation is turned on (web scraping, brute force, proactive bot defense, dos client side mitigation).

Workaround

N/A

Fix Information

We added internal parameters that control an exclusion list of URLs and/or headers that appear in the request. The bigdb parameter names are: dosl7.cs_excluded_urls and dosl7.cs_excluded_headers. These parameters are used by DoS Layer 7 and the Enforcer.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips