Basic CSRF protection in AVI Load Balancer 22.1.x version
search cancel

Basic CSRF protection in AVI Load Balancer 22.1.x version

book

Article ID: 391489

calendar_today

Updated On:

Products

VMware Avi Load Balancer

Issue/Introduction

Basic CSRF protection in AVI Load Balancer 22.1.x version can be done via checking of the Referer Header.

Environment

AVI Load balancer Version: 22.1.x

Resolution

CSRF protection in AVI Load Balancer 22.1.x version can be implemented using HTTP security policy on the Virtual service.

Please follow below steps to create HTTP security policy under a Virtual service.

>> Edit the Virtual service >> Policies >> HTTP Security

Click "+" symbol to add new Rule and Enter rule name of your choice

Select "Headers" in the match category.

 

>> Add the Criteria and Name as mentioned below provide the values based on the requirement.

Note: Please add all the required URLs in the values section.

>> Please select an Action when this criteria is met. 

Note: 403 response is selected for illustration purpose.

Additional Information