Citrix ADC

Managing CSRF form tagging check relaxations

You configure an exception (or relaxation) to the CSRF Form Tagging security check in the Add Cross-Site Request Forgery Tagging Check Relaxation dialog box or the Modify Cross-Site Request Forgery Tagging Check Relaxation dialog box.

配置一个CSRF形式标记检查放松by using the GUI

  1. Navigate toSecurity > Citrix Web App Firewall > Profiles.

  2. In theProfilespane, select the profile you want to configure, and then clickOpen.

  3. In theConfigure Web App Firewall Profiledialog box, click theSecurity Checkstab. TheSecurity Checkstab contains the list of Web App Firewall security checks.

  4. To add or modify a CSRF relaxation, do one of the following:

    • To add a new relaxation, click Add.
    • To modify an existing relaxation, select the relaxation that you want to modify, and then clickOpen.

    TheAdd Cross-Site Request Forgery Tagging Check RelaxationorModify Cross-Site Request Forgery Tagging Check Relaxationdialog box is displayed. Except for the title, these dialog boxes are identical.

  5. Fill in the dialog box as described below.

    • Enabled check box—Select to place this relaxation or rule in active use; clear to deactivate it.

    • Form Origin URL—In the text area, enter a PCRE-format regular expression that defines the URL that hosts the form.

    • Form Action URL—In the text area, enter a PCRE-format regular expression that defines the URL to which data entered into the form is delivered.

    • Comments—In the text area, type a comment. Optional.

    Note:

    For any element that requires a regular expression, you can type the regular expression, use theRegex Tokensmenu to insert regular expression elements and symbols directly into the text box, or clickRegex Editorto open theAdd Regular Expressiondialog box, and use it to construct the expression.

  6. ClickOK. TheAdd Cross-Site Request Forgery Tagging Check RelaxationorModify Cross-Site Request Forgery Tagging Check Relaxationdialog box closes and you return to theModify Cross-Site Request Forgery Tagging Checkdialog box.

  7. To remove a relaxation or rule, select it, and then clickRemove.

  8. To enable a relaxation or rule, select it, and then clickEnable.

  9. To disable a relaxation or rule, select it, and then clickDisable.

  10. To configure the settings and relationships of all existing relaxations in an integrated interactive graphic display, clickVisualizer, and use the display tools.

  11. To review and configure learned rules for the CSRF check, clickLearningand perform the steps inTo configure and use the Learning feature.

  12. ClickOK.

Managing CSRF form tagging check relaxations