WAF Rules blocking Clarity navigation
search cancel

WAF Rules blocking Clarity navigation

book

Article ID: 187996

calendar_today

Updated On:

Products

Clarity PPM On Premise

Issue/Introduction

When using a Web Application Firewall with Clarity, we observed that Clarity New UX/ Old UX navigation is being blocked by the firewall citing different issues.

Environment

Release : All Supported Clarity Release

Cause

Web Application firewall scans the URL for potential threats/vulnerabilities based on the URL. Depending on the rules enforced all those requests are blocked by WAF and are not sent to Clarity Web server causing unexpected behavior on the application

Resolution

  • Broadcom Clarity Team recommends to deploy WAF at detect mode in non production
  • Capture the WAF logs from the detect mode and create a policy for exception 
  • Post that WAF can be enabled at block mode in production 
  • Ensure no URL's are blocked by WAF in production 
  • Clarity doesn't do an URL scan but we do an application level tests based on the data received and prevent popular web application vulnerabilities.
  • If there are any new vulnerabilities found in the application, we will address then as part of a Application Patch or Application Release