18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 6: Configuring Application Defenses<br />

Creating Web or Secure Web Application Defenses<br />

About the HTTP<br />

Reply tab<br />

164<br />

The HTTP Reply tab allows you to configure header filtering for HTTP replies.<br />

Follow the steps below.<br />

Note: The fields in this tab will be disabled unless you select the HTTP Reply<br />

check box on the Enforcements tab. Also, this tab is not available for Secure Web if<br />

you select Client in the Type field.<br />

1 In the Filter Option field, determine whether you want to allow or deny the<br />

header types you select, as follows:<br />

• Allow—Select this option to allow all header types that are selected in<br />

the HTTP Reply Header Filter Types window. All other types will be<br />

denied.<br />

• Deny—Select this option to deny all header types that are selected<br />

selected in the HTTP Reply Header Filter Types window. All other types<br />

will be allowed.<br />

2 Select the type <strong>of</strong> HTTP header filtering you want to allow or deny in the<br />

Selected HTTP Reply Header Filter Types area. The following options are<br />

available:<br />

Note: The X-* filter type is a wildcard filter that will allow or deny all X-xxx reply<br />

headers (commonly found in user-defined headers). If you create an Allow list<br />

and do not include the X-* filter type, most Web traffic will be denied.<br />

• None—Select this option if you want to deselect all HTTP reply header<br />

filter types in the list. (You can also deselect all <strong>of</strong> the types by clicking<br />

Deselect All.)<br />

• Standard—Select this option if you want to automatically select all <strong>of</strong> the<br />

header types contained in the list. (You can also select all header types<br />

by clicking Select All.)<br />

• Paranoid—Select this option if you want to exclude all options not<br />

defined in the RFC.<br />

• Custom—Select this option if you want to manually configure which<br />

HTTP reply header types you will allow or deny.<br />

3 In the Denied Header Action area, select one <strong>of</strong> the following options:<br />

• Block Entire Page—Select this option to block the entire page when an<br />

HTTP reply header is denied.<br />

• Allow Page Through Without Denied Headers—Select this option to<br />

mask the denied HTTP reply header, but still allow the page to be<br />

viewed. (A denied HTTP reply header will be scrubbed.)

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!