F5 WAF blocks pega packet over cookies pega-perf contains "&start"
F5 WAF detects and blocks pega packets that contains 2&start inside pega-perf in cookies:
Cookie: Pega-Perf=itkn=2&start; Pega-RULES= {pd}AAAAAR8M/Nqm....
This leads to pega page freezes and stuck on blank screen
Can you please show us what is '&start' for ?
If this value is optional , how do I not pass this value into the cookies?
F5 log
Violation Details
Attack signature detected [1]
Detected Keyword |
itkn=2&start |
Attack Signature | StagedID
200003654 Name"start" execution attempt (Parameter) |
Context | Cookie |
Actual Cookie Name |
Pega-Perf |
Wildcard Cookie Name | Staged
* |
Cookie Value | itkn=2&start |
Applied Blocking Settings | Staged Likely False Positive |