# WAF URL Whitelist syntax

**URL:** <https://community.a10networks.com/t/waf-url-whitelist-syntax/402>\
**Category:** CFW - Convergent Firewall\
**Created:** [July 6, 2016, 4:10pm UTC](https://community.a10networks.com/t/waf-url-whitelist-syntax/402 "2016-07-06T16:10:14Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![rwilliams](https://avatars.discourse-cdn.com/v4/letter/r/74df32/32.png) [@rwilliams](https://community.a10networks.com/u/rwilliams)\
**Post date:** [July 6, 2016, 4:10pm UTC](https://community.a10networks.com/t/waf-url-whitelist-syntax/402/1 "2016-07-06T16:10:14Z")

</div>

Hi All,

I am trying to write an additional policy based on the default url whitelist in the WAF templates. However the whitelist keeps failing the check due to a syntax error, but I can not see where it is, and I can’t find any documentation on the syntax for creating the files.

What I have is the following:

# This is a comment

```auto
root,^/$
static,^[^?]\+[.](?:html?|shtml|js|gif|jpg|jpeg|png|swf|pif|pdf|css|csv|ico)$
dynamic,^[^?]\+[.](?:cgi|aspx?|jsp|php|pl)(?:[?].\*)?$
permitted,^(https?:\\/\\/)?(?:[a-z\\.]\{2\}|test)\\-(?:ws|acl)\\.subdomain.domain(?:com?|org)\\/path1\\/(?:about|index)$

```

I know that the regex I am using:

```auto
^(https?:\\/\\/)?(?:[a-z\\.]\{2\}|test)\\-(?:ws|acl)\\.subdomain.domain(?:com?|org)\\/path1\\/(?:about|index)$

works as I put it into a online tester and it permits the URL to the correct structure. however in the WAF policy it is rejected. 

```

Do the policies using proper RegEx?

Please help.

Kind Regards

Ryan

---

<div class="post-metadata">

**Author:** ![tmitsuhata](https://avatars.discourse-cdn.com/v4/letter/t/3bc359/32.png) [@tmitsuhata](https://community.a10networks.com/u/tmitsuhata)\
**Post date:** [July 6, 2016, 6:57pm UTC](https://community.a10networks.com/t/waf-url-whitelist-syntax/402/2 "2016-07-06T18:57:47Z")

</div>

Hi Ryan,  
it seems that ACOS device doesn’t like brackets “( )” around “https://”. Please try without them.

```auto
ACOS(config)\#waf policy create aaa 
Type in your WAF policy file (type . on a line by itself when done)
permitted,^https?:\\/\\/?(?:[a-z\\.]\{2\}|test)\\-(?:ws|acl)\\.subdomain.domain(?:com?|org)\\/path1\\/(?:about|index)$

```

.  
WAF policy aaa created; syntax check passed

Hope this works for you.  
Thanks!

---

<div class="post-metadata">

**Author:** ![rwilliams](https://avatars.discourse-cdn.com/v4/letter/r/74df32/32.png) [@rwilliams](https://community.a10networks.com/u/rwilliams)\
**Post date:** [July 7, 2016, 11:01am UTC](https://community.a10networks.com/t/waf-url-whitelist-syntax/402/3 "2016-07-07T11:01:32Z")

</div>

Hi,

Thanks for that. It is now active with no syntax errors. However, what I am now seeing is that the whitelist policy is now denying what should be an acceptable URL. To try and get to the bottom I have even shortened the regex to just the host domain, with out caring about the path.

so the regex currently looks like this:

```auto
permitted,^https?:\\/\\/?(?:[a-z\\.]\{2\}|test)\\-(?:ws|acl)\\.subdomain\\.domain\\.(?:com|org)\\/\*

```

which in theory should allow the following URL:

[https://test-ws.subdomain.domain.com/path1/about](https://test-ws.subdomain.domain.com/path1/about)

however looking at the WAF logs I see the following:

```auto
act=deny md=learn svc=https req="GET /path1/about HTTP/1.1" 0 msg="Whitelist match failed! URI /path1/about"

I can not see why the Policy is denying the URI when the regex should allow it. again I have checked the regex using an online tester and it appears good and matches.

```

Any help appreciated.

Rgrds

Ryan

---

<div class="post-metadata">

**Author:** ![rwilliams](https://avatars.discourse-cdn.com/v4/letter/r/74df32/32.png) [@rwilliams](https://community.a10networks.com/u/rwilliams)\
**Post date:** [July 7, 2016, 12:39pm UTC](https://community.a10networks.com/t/waf-url-whitelist-syntax/402/4 "2016-07-07T12:39:14Z")

</div>

ok so further to my last I stripped the regex back completely to the following:

```auto
permit, ^[^?]\*\\/about

```

and this worked and I could see the uri whitelist passing. So I started to restrict it a little more with a path as follows:

```auto
messaging,^[^?]\*\\/path1\\/about

```

and this worked also with the URL [https://test-ws.subdomain.domain.local/path1/about](https://test-ws.subdomain.domain.local/path1/about). So I then added the option to allow 2 distinct destinations as follows:

```auto
messaging,^[^?]\*\\/path1\\/(?:about|SomeWherElse)

```

I then tried the URLs

[https://test-ws.subdomain.domain.local/path1/about](https://test-ws.subdomain.domain.local/path1/about)  
[https://test-ws.subdomain.domain.local/path1/SomeWhereElse](https://test-ws.subdomain.domain.local/path1/SomeWhereElse)

The result was that the 1st URL worked fine, but the second URL using SomeWhereElse failed and the WAF policy log showed that it was denied:

Jul 7 12:33:50 172.30.1.10 CEF:1|A10|TH3030S|4.1.0-P1|WAF|Jul 07 2016 12:33:50|uri-wlist-check|6|src=10.65.111.180 spt=19793 dst=172.30.1.101 dpt=443 hst=“test-ws.subdomain.domain” cs1=ws-test-WAF-Template cs2=5f2f66c39429c9f9 act=deny md=learn svc=https req=“GET /Path1/SomeWhereElse HTTP/1.1” 0 msg=“Whitelist match failed! URI /path1/SomeWhereElse”  
again the regex was tested using an online tester and checked out ok with either destination.

Anyone see anything wrong?

thanks

Ryan

---

<div class="post-metadata">

**Author:** ![rwilliams](https://avatars.discourse-cdn.com/v4/letter/r/74df32/32.png) [@rwilliams](https://community.a10networks.com/u/rwilliams)\
**Post date:** [July 7, 2016, 1:59pm UTC](https://community.a10networks.com/t/waf-url-whitelist-syntax/402/5 "2016-07-07T13:59:23Z")

</div>

so some more stripped back.

the waf profile regex:

the regex:

```auto
messaging,^[^?]\*\\/about$

```

WILL match the URL [https://test-ws.subdomain.domain.local/path1/about](https://test-ws.subdomain.domain.local/path1/about)

Where as the regex:

```auto
messaging,^[^?]\*\\/SomeWhereElse$

```

Does NOT match the URL [https://test-ws.subdomain.domain.local/path1/SomeWhereElse](https://test-ws.subdomain.domain.local/path1/SomeWhereElse)

However the regex:

```auto
messaging,^[^?]\*\\/somewhereelse$

```

WILL match [https://test-ws.subdomain.domain.local/path1/somewhereelse](https://test-ws.subdomain.domain.local/path1/somewhereelse)

So the only difference being the use of upper case in the regex and URI destination.

How do I get the regex to match the letter case? The URI has to be mixed case and connot be changed.  
Regards

Ryan

---

<div class="post-metadata">

**Author:** ![rwilliams](https://avatars.discourse-cdn.com/v4/letter/r/74df32/32.png) [@rwilliams](https://community.a10networks.com/u/rwilliams)\
**Post date:** [July 7, 2016, 2:11pm UTC](https://community.a10networks.com/t/waf-url-whitelist-syntax/402/6 "2016-07-07T14:11:00Z")

</div>

So finally saw that the regex:

```auto
messaging,^[^?]\*\\/somewhereelse$

```

will match the correct URI of [https://test-ws.subdomain.domain.local/path1/SomeWhereElse](https://test-ws.subdomain.domain.local/path1/SomeWhereElse)

So the policy regex has to be in LOWER case in order to work? Is there any way I can get the regex to match the exact Mixed CASE that is in the URI??

As part of the Web Application Firewall I thought you should be able to match the exact URI with regards to the use of UPPER or lower case..  
I will continue to work on it to lock down the rest of the URL.

Regards

Ryan

---

<div class="post-metadata">

**Author:** ![tmitsuhata](https://avatars.discourse-cdn.com/v4/letter/t/3bc359/32.png) [@tmitsuhata](https://community.a10networks.com/u/tmitsuhata)\
**Post date:** [July 9, 2016, 1:23am UTC](https://community.a10networks.com/t/waf-url-whitelist-syntax/402/7 "2016-07-09T01:23:58Z")

</div>

Hi Ryan,  
It seems that ACOS doesn’t like the case insensitive option (?i).  
Have you tried something like this ‘[Ss]ome[Ww]here[Ee]lse’ instead?

Good luck.

Thanks,  
Taka

---

<div class="post-metadata">

**Author:** ![rwilliams](https://avatars.discourse-cdn.com/v4/letter/r/74df32/32.png) [@rwilliams](https://community.a10networks.com/u/rwilliams)\
**Post date:** [July 13, 2016, 10:02am UTC](https://community.a10networks.com/t/waf-url-whitelist-syntax/402/8 "2016-07-13T10:02:27Z")

</div>

Hi Taka,

Thought you might like an update. In the end I logged a call with support and it turns out and I quote from support:

> “In our current WAF implementation, the WAF converts entire URI and arguments to lowercase prior to any matching. However, while forwarding the request to the back-send server, A10 uses the original request URI.”

Additionally, the WAF whitelist/blacklist will only work on the path section of the URL. It does not deal with the protocol (http/https) or host section.

So support ended up crafting an aFleX script for me to deal with the strict URL schema I wanted to employ, including both host and case sensitive path.

All work now. Thanks for your input into this. much appreciated.

Thanks Ryan

---

<div class="post-metadata">

**Author:** ![tmitsuhata](https://avatars.discourse-cdn.com/v4/letter/t/3bc359/32.png) [@tmitsuhata](https://community.a10networks.com/u/tmitsuhata)\
**Post date:** [July 14, 2016, 11:29pm UTC](https://community.a10networks.com/t/waf-url-whitelist-syntax/402/9 "2016-07-14T23:29:02Z")

</div>

Hi Ryan,  
That’s good to know. Thanks for sharing!

Thanks,  
Taka

---

<div class="post-metadata">

**Author:** ![GFR](https://avatars.discourse-cdn.com/v4/letter/g/258eb7/32.png) [@GFR](https://community.a10networks.com/u/GFR)\
**Post date:** [October 4, 2024, 10:45pm UTC](https://community.a10networks.com/t/waf-url-whitelist-syntax/402/10 "2024-10-04T22:45:57Z")

</div>

As of october 2024 do the same considerations still apply to current versions of WAF?

---

<div class="post-metadata">

**Author:** ![mdunn](https://avatars.discourse-cdn.com/v4/letter/m/87869e/32.png) [@mdunn](https://community.a10networks.com/u/mdunn)\
**Post date:** [October 14, 2024, 3:42pm UTC](https://community.a10networks.com/t/waf-url-whitelist-syntax/402/11 "2024-10-14T15:42:42Z")

</div>

Yes, but the future of A10 WAF is NGWAF: [A10 Defend Next-Gen Web Application Firewall | A10 Networks](https://www.a10networks.com/products/a10-next-gen-waf/)
