Create a CSP (Content-Security-Policy) rule





How to create a content security policy rule on the LoadMaster


LoadMaster administrator would like to add Content-Security-Policy headers for Exchange traffic.

Cause: Content Security Policy (CSP) is an added layer of security that helps to detect and mitigate certain types of attacks, including Cross-Site Scripting (XSS) and data injection attacks

These attacks are used for data theft, site defacement, and malware distribution.

Create a CSP rule to mitigate potential malicious requests:

One example would be an "Add Header" rule.     

  • Header Field to be Added: Content-Security-Policy
  • Value of Header Field to be Added: default-src 'none'; script-src 'self'; connect-src 'self'; img-src 'self'; style-src 'self';base-uri 'self';form-action 'self';

       Once the rule has been created, apply it to the desired VS.
       Advanced Properties > HTTP Header Modifications > Response Rules > Add Rule.

Notes: CSP-Evaluator

