Forum Discussion

mobo_139370's avatar
mobo_139370
Icon for Nimbostratus rankNimbostratus
Mar 10, 2015

ASM DOS Protection heavy URLs

Hi,

 

I wanted to have a simple/praticable explantation of the new option of the DoS profile : heavy URLs.

 

I read the official documentation and some articles and Q/A in devcentral but I just want to know if my understanding is correct : For the listed heavy URLs, ASM will not apply the same thresholds as for other URLs ? Will these Thresholds be bigger or smaller ? some examples will be helpfull.

 

Thanks,

 

2 Replies

  • Hi,

     

    Heavy URL protection specifies, when enabled (by default), that whenever an attack is detected the system protects the heavy URLs using the URL-based methods that you enabled in the Prevention Policy area (sending a JavaScript challenge to each suspicious URLs address and waiting for a response or the system drops transactions for suspicious URLs). If no URL-based methods are enabled, the system only reports attacks.