Dell SonicWALL Secure Mobile Access 8.5
Administration Guide
284
transported only in HTTPS connections. Both together add a strong layer of security for the server-side
cookies.
6 For
Client Cookies
, select
Allow
if an application on the portal needs all of the client cookies. When
disabled, client-side cookies are not allowed to be sent to the backend systems. This option does not
affect server-side cookies.
7 For the
Exclusion List
, select
Enabled
to display additional fields for configuration.
8 To enter a custom cookie name and path to the
Exclusion List
, click in the
Cookie Name
field to type in
the name of the cookie, and click in the
Cookie Path
field to type in the path. Then click >
Add
.
9 To add one or more already-detected cookies to the
Exclusion List
, select the desired cookies in the
Detected Cookies
list, holding the
Ctrl
key while clicking multiple cookies, and then click <
Add
to add
them to the
Exclusion List
.
10 To remove cookies from the
Exclusion List
, select the cookies to be removed and then click
Remove
.
11 To clear the
Detected Cookies
list, click
Clear
.
12 When finished, click
Accept
.
Configuring Web Site Cloaking
Under
Web Site Cloaking
, you can filter out headers in response messages that could provide information to
clients about the backend Web server that could possibly be used to find a vulnerability.
To configure Web site cloaking:
1 Expand the
Web Site Cloaking
section.
2 In the
Block Response Header
fields, type the server host name into the first field and type the header
name into the second field, then click
Add
.
For example, if you set the host name to “webmail.xyz.com” and the header name to “X-OWA-version,”
headers with the name “X-OWA-version” from host “webmail.xyz.com” is blocked. In general, listed
headers are not sent to the client if an HTTP/HTTPS bookmark or off-loaded application is used to access
a listed Web server.
To block a certain header from all hosts, set the host name to an asterisk (*). You can add up to 64
host/header pairs. In the HTTP protocol, response headers are not case-sensitive.
3 To remove a host/header pair from the list to be blocked, select the pair in the text box and then click
Remove
.
NOTE:
Blocking does not occur for headers such as Content-Type that are critical to the
HTTP protocol.