Prechádzať zdrojové kódy

Excludes WAF rules that are blocking legit traffic for Cust SH

To be tagged v4.3.10
Fred Damstra [afs macbook] 3 rokov pred
rodič
commit
3cf06ff404

+ 4 - 2
base/splunk_servers/customer_searchhead/waf.tf

@@ -14,12 +14,14 @@ module "waf" {
 
   excluded_rules_AWSManagedRulesCommonRuleSet = [
     "SizeRestrictions_BODY",
+    "SizeRestrictions_QUERYSTRING",
     "RestrictedExtensions_URIPATH",
     "EC2MetaDataSSRF_BODY",
-    "GenericLFI_BODY"
+    "GenericLFI_BODY",
   ]
   excluded_rules_AWSManagedRulesSQLiRuleSet = [
-    "SQLi_QUERYARGUMENTS"
+    "SQLi_QUERYARGUMENTS",
+    "SQLi_BODY",
   ]
 
   # These are passed through and should be the same for module