cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Who Me Too'd this topic

How to detect domain fronting

L2 Linker

Hi,

 

did anyone manage to write a custom signature to detect domain fronting?

PA extracts the Host header, so in theory it should be possible to detect if the Host header is different from the URL?

 

Alternatively, if one could log the Host header one could develop external detection logic in a SIEM.

 

Regards,

    Andreas

Who Me Too'd this topic