How to Configure a frame-ancestors response header with a list specifying (Global Protect portal)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

How to Configure a frame-ancestors response header with a list specifying (Global Protect portal)

L4 Transporter

Hello
I am reviewing that GlobalProtect (vpn.xxxxxx.com and remote.xxxxxx.com) are vulnerable as they do not have a frame-ancestors response header configured.

I want to configure a frame-ancestors response header with a list specifying which URLs can embed site elements; or use the 'none' keyword to deny any site from embedding site content; or use the 'self' keyword to allow only the site serving the content to embed it.

Can you tell us how to proceed with this configuration?

It is possible?

Regards

1 REPLY 1

L0 Member

This will soon be fixed in the Panos code. The none option will be appended. 

  • 997 Views
  • 1 replies
  • 1 Likes
  • 47 Subscriptions
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!