Bug ID 826625: FPS does not respect HTTP profile's HSTS configuration

Last Modified: Jun 10, 2021

Bug Tracker

Affected Product:  See more info
BIG-IP FPS(all modules)

Known Affected Versions:
13.1.0,,,,,,,,, 13.1.1,,,,, 13.1.3,,,,,,, 13.1.4,, 14.0.0,,,,,, 14.0.1,, 14.1.0,,,,,, 14.1.2,,,,,,,,, 14.1.3,, 14.1.4,,,, 15.0.0, 15.0.1,,,,, 15.1.0,,,,,, 15.1.1, 15.1.2,, 15.1.3

Opened: Sep 15, 2019
Severity: 3-Major


FPS plugin does not respect Strict-Transport-Security configuration and as a result, responses for FPS self URLs does not contain the Strict-Transport-Security header


FPS responses do not include the Strict-Transport-Security header.


-- Virtual server has a http profile where 'HTTP Strict Transport Security' mode is enabled. -- Virtual server has a FPS profile attached.


Use iRules according to your configuration/requirements: HTTP::header insert Strict-Transport-Security ...

Fix Information


Behavior Change