SV-91115r1_rule
V-76419
SRG-NET-000169-ALG-000102
AKSD-WF-000018
CAT II
10
Configure Kona Site Defender to not modify origin-defined HTTP session headers:
1. Log in to the Akamai Luna Portal (Caution-https://control.akamai.com).
2. Click the "Configure" tab and select "Site" under the "Property" section.
3. If prompted for which product to use, select "Site Defender" and then "Continue".
4. Click on the applicable configuration.
5. Click on the applicable version of the configuration.
6. Search the "Property Configuration Settings" and remove any of the following behaviors that are modifying origin-defined HTTP session headers:
"Modify Incoming Request Header"
"Modify Incoming Response Header"
"Modify Outgoing Request Header"
"Modify Outgoing Response Header"
OR
Contact the Akamai Professional Services team to implement the changes at 1-877-4-AKATEC (1-877-425-2832).
Confirm Kona Site Defender is not stripping origin-defined HTTP session headers:
1. Log in to the Akamai Luna Portal (Caution-https://control.akamai.com).
2. Click the "Configure" tab and select "Site" under the "Property" section.
3. If prompted for which product to use, select "Site Defender" and then "Continue".
4. Click on the applicable configuration.
5. Click on the applicable version of the configuration.
6. Click the "View XML" button.
7. Search the XML text for the following fields and confirm that no origin session headers are being added or removed:
"edgeservices:modify-incoming-request.remove-header"
"edgeservices:modify-incoming-request.add-header"
"edgeservices:modify-incoming-response.remove-header"
"edgeservices:modify-incoming-response.add-header"
"edgeservices:modify-outgoing-request.remove-header"
"edgeservices:modify-outgoing-request.add-header"
"edgeservices:modify-outgoing-response.remove-header"
"edgeservices:modify-outgoing-response.add-header"
If Kona Site Defender is stripping origin-defined HTTP session headers, this is a finding.
V-76419
False
AKSD-WF-000018
Confirm Kona Site Defender is not stripping origin-defined HTTP session headers:
1. Log in to the Akamai Luna Portal (Caution-https://control.akamai.com).
2. Click the "Configure" tab and select "Site" under the "Property" section.
3. If prompted for which product to use, select "Site Defender" and then "Continue".
4. Click on the applicable configuration.
5. Click on the applicable version of the configuration.
6. Click the "View XML" button.
7. Search the XML text for the following fields and confirm that no origin session headers are being added or removed:
"edgeservices:modify-incoming-request.remove-header"
"edgeservices:modify-incoming-request.add-header"
"edgeservices:modify-incoming-response.remove-header"
"edgeservices:modify-incoming-response.add-header"
"edgeservices:modify-outgoing-request.remove-header"
"edgeservices:modify-outgoing-request.add-header"
"edgeservices:modify-outgoing-response.remove-header"
"edgeservices:modify-outgoing-response.add-header"
If Kona Site Defender is stripping origin-defined HTTP session headers, this is a finding.
M
3165