Dell SonicWall SRA 4200 Administrator's Manual page 267

Sra 6.0
Table of Contents

Advertisement

Table 17 on page 267 describes the available variables.
Table 17
Variables for Use in Rules
Variable Name
Collection
Host
No
URI
No
HTTP Method
No
HTTP Status Code
No
Parameter Values
Yes
Parameter Names
Yes
Remote Address
No
Request Header
Yes
Values
Request Header
Yes
Names
Response Header
Yes
Values
Description
Refers to the host name or the IP address in the Host header of an
HTTP request. This typically refers to the host part of the URL in the
address bar of your browser.
Refers to the combination of path and the query arguments in a URL.
Refers to the method, such as GET and POST, used by the browser
to request a resource on the Web server.
Refers to the response status from the Web server. You can use this
to configure actions for various error codes from the Web server.
Refers to the collection of all request parameter values, including the
values of all query arguments and form parameters that are part of
the current request.
To match against some aspect of the entire list of parameter values,
such as the number of parameter values, leave the selection field
empty.
To match against the value of a particular parameter, specify the
name of the parameter in the selection field to the right of the colon.
Refers to the collection of all request parameter names, including the
names of all query arguments and form parameters that are part of
the current request.
To match against some aspect of the entire list of parameter names,
leave the selection field empty.
To match against the name of a particular parameter, specify the
parameter name in the selection field to the right of the colon.
Refers to the client's IP address. This variable allows you to allow or
block access from certain IP addresses.
Refers to the collection of all HTTP(S) request header values for the
current request.
To match against some aspect of the entire list of request header val-
ues, leave the selection field empty.
To match against a particular header value, specify the name of the
header in the selection field to the right of the colon.
For example, to block Ajax requests, select Request Header Values
as the Variable, specify X-Request-With in the selection text box,
and specify ajax in the Value field.
Refers to the collection of all HTTP(S) request header names for the
current request.
To match against some aspect of the entire list of request header
names, leave the selection field empty.
To match against a particular header name, specify the name of the
header in the selection field to the right of the colon.
For example, to block requests that are not referred by a trusted host,
select Request Header Names as the Variable, specify Referer in
the selection text box, enter the host names or IP addresses of the
trusted hosts in the Value field, select the Not check box and select
the Matches Keyword operator.
Refers to the collection of all HTTP(S) response header values for
the current request.
To match against some aspect of the entire list of response header
values, leave the selection field empty.
To match against a particular header value, specify the name of the
header in the selection field to the right of the colon.
Web Application Firewall Configuration | 267

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents