Managing content types
To set the default request content type by using the command line interface
-
set appfw profile <name> -requestContentType <type> -
save ns config
Example
set appfw profile profile1 -requestContentType "text/html"
save ns config
To remove the user-defined default request content type by using the command line interface
-
unset appfw profile <name> -requestContentType <type> -
save ns config
Example
unset appfw profile profile1 -requestContentType "text/html"
save ns config
To set the default response content type by using the command line interface
-
set appfw profile <name> -responseContentType <type> -
save ns config
Example
set appfw profile profile1 -responseContentType "text/html"
save ns config
To remove the user-defined default response content type by using the command line interface
-
unset appfw profile <name> -responseContentType <type> -
save ns config
Example
unset appfw profile profile1 -responseContentType "text/html"
save ns config
To add a content type to the allowed content types list by using the command line interface
-
bind appfw profile <name> -ContentType <contentTypeName> -
save ns config
Example
bind appfw profile profile1 -contentType "text/shtml"
save ns config
To remove a content type from the allowed content types list by using the command line interface
-
unbind appfw profile <name> -ContentType <contentTypeName> -
save ns config
Example
unbind appfw profile profile1 -contentType "text/shtml"
save ns config
Manage urlencoded and multipart-form content types
bind appfw profile p2 -contentType <string>
bind appfw profile p2 -contentType UrlencodedFormContentType
bind appfw profile p2 -ContentType appfwmultipartform
To manage the default and allowed content types by using the GUI
-
Navigate to Security > Web App Firewall > Profiles.
-
In the details pane, select the profile that you want to configure, and then click Edit. The Configure Web App Firewall Profile dialog box is displayed.
-
The Configure Web App Firewall Profile dialog box, click the Settings tab.
-
On the Settings tab, scroll down about halfway to the Content Type area.
-
In the Content Type area, configure the default request or response content type:
-
To configure the default request content type, type the MIME/type definition of the content type you want to use in the Default Request text box.
-
To configure the default response content type, type the MIME/type definition of the content type you want to use in the Default Response text box.
-
To create a new allowed content type, click Add. The Add Allowed Content Type dialog box is displayed.
-
To edit an existing allowed content type, select that content type, and then click Open. The Modify Allowed Content Type dialog box is displayed.
-
-
To manage the allowed content types, click Manage Allowed Content Types.
-
To add a new content type or modify an existing content type, click Add or Open, and in the Add Allowed Content Type or Modify Allowed Content Type dialog box, do the following steps.
-
Select/clear the Enabled check box to include the content type in, or exclude it from, the list of allowed content types.
-
In the Content Type text box, type a regular expression that describes the content type that you want to add, or change the existing content type regular expression.Content types are formatted exactly as MIME type descriptions are.Note:You can include any valid MIME type on the allowed contents type list. Since many types of document can contain active content and therefore can potentially contain malicious content, you must exercise caution when adding MIME types to this list.
-
Provide a short description that explains the reason for adding this particular MIME type to the allowed contents type list.
-
Click Create or OK to save your changes.
-
-
Click Close to close the Manage Allowed Content Types dialog box and return to the Settings tab.
-
Click OK to save your changes.
To manage Urlencoded and Multipart-form content types by using the NetScaler GUI
-
Navigate to Security > Web App Firewall > Profiles.
-
In the details pane, select the profile that you want to configure, and then click Edit.
-
In the Configure Web App Firewall Profile page, select the Profile Settings in the Advanced Settings section.
-
Under Inspected Content Type section, set the following parameters:
-
application/x-www-form-urlencoded. Select the checkbox to inspect Urlencoded content type.
-
multipart/form-data. Select the check to inspect Multipart-form content type.
-
-
Click OK.