When using a Web Application Firewall with Clarity, we observed that Clarity New UX/ Old UX navigation is being blocked by the firewall citing different issues.
Environment
Release : All Supported Clarity Release
Cause
Web Application firewall scans the URL for potential threats/vulnerabilities based on the URL. Depending on the rules enforced all those requests are blocked by WAF and are not sent to Clarity Web server causing unexpected behavior on the application
Resolution
Broadcom Clarity Team recommends to deploy WAF at detect mode in non production
Capture the WAF logs from the detect mode and create a policy for exception
Post that WAF can be enabled at block mode in production
Ensure no URL's are blocked by WAF in production
Clarity doesn't do an URL scan but we do an application level tests based on the data received and prevent popular web application vulnerabilities.
If there are any new vulnerabilities found in the application, we will address then as part of a Application Patch or Application Release