Loading...
Loading...
When multiple POST request arrive while access policy is being evaluated, the second POST request is lost.
- Browser will follow 302 redirect, and resubmit GET to "https://hostname/application". Second POST request is now lost! - BIG-IP will redirect user to /my.logout.php3 and will start evaluating access policy. After access policy is completed, POST request will be gone.
- Create a simple access policy with a login page. Assign it to virtual. - Generate a POST request to virtual (e.g. https://hostname/application). This is a first request to hit BIG-IP. User does not have a session/cookie yet. - BIG-IP will respond with 302 redirecting user to /my.policy: HTTP/1.0 302 Found Server: BigIP Connection: Close Content-Length: 0 Location: /my.policy - Do not enter any credentials on the login page. Instead generate another POST request to the same virtual (e.g. https://hostname/application). Second request sent to big-ip will contain a session cookie. - This second POST will result in 302 redirect to "https://hostname/application". (NOTE: Expected behavior: display error message)
None.
None
Click on a version to see all relevant bugs
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.