cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who Me Too'd this topic

How to Configure a frame-ancestors response header with a list specifying (Global Protect portal)

L4 Transporter

Hello
I am reviewing that GlobalProtect (vpn.xxxxxx.com and remote.xxxxxx.com) are vulnerable as they do not have a frame-ancestors response header configured.

I want to configure a frame-ancestors response header with a list specifying which URLs can embed site elements; or use the 'none' keyword to deny any site from embedding site content; or use the 'self' keyword to allow only the site serving the content to embed it.

Can you tell us how to proceed with this configuration?

It is possible?

Regards

Who Me Too'd this topic