Manual Chapter : Configuring referrer checks

Applies To:

  • BIG-IP FPS

    21.0.0, 17.5.1, 17.5.0, 17.1.3, 17.1.2, 17.1.1, 17.1.0, 17.0.0, 16.1.6, 16.1.5, 16.1.4, 16.1.3, 16.1.2, 16.1.1, 16.1.0, 16.0.1, 16.0.0, 15.1.9, 15.1.8, 15.1.7, 15.1.6, 15.1.5, 15.1.4, 15.1.3, 15.1.2, 15.1.0

Configuring referrer checks

Configure referrer checks on an anti-fraud profile if you want the system to examine requests for resources on web pages in the anti-fraud profile that come from domains outside of the anti-fraud profile.

  1. On the Main tab, click Security > Fraud Protection Service > Anti-Fraud Profiles.

    The Anti-Fraud Profiles screen opens.

  2. From the list of profiles, select the profile on which you want to configure referrer checks.

    The Anti-Fraud Profile Properties screen opens.

  3. In the Anti-Fraud Configuration area, select Advanced and then Phishing Detection.

    The Phishing Detection screen opens.

  4. Select the Enabled check box for the Referrer Checks setting.

    The Referrer Checks configuration options are displayed.

  5. In the Referrer Domain Whitelist field, type a list of external domains that are allowed to request resources from the protected web application.

  6. In the Check referrer header value in requests to these URLs field, type a list of URLs on which the system checks the referrer header value in the htttp request to determine if the request may have come from a phishing site.

    Note: If you want the system to check referrer header value in http requests from URLs ending in a specific file type, type *. and then the file type. For example, if you want the system to check the referrer header value in requests from URLs ending with .gif, type *.gif.

  7. In the Ignore referrer checks for these URLs field, type a list of URLs where the system should not examine the referrer header value in requests.

  8. Click Save.

    The anti-fraud profile is updated with the changes you made.