Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How can I bypass the WAF error of ModSecurity: Request body no files data length is larger than the configured limit?

I am currently running Sophos UTM 9.315-2. The Web Application Firewall is blocking traffic that is a POST over a certain size. The web application needs to post this size of a page. Currently it returns an HTTP 413 and then the Web Application Firewall logs:

ModSecurity: Request body no files data length is larger than the configured limit (1048576)

I can see no way to disable this other than turning off the Web Application Firewall. No rule ID or other identifier is given to exclude it. I've found some online references to modifying the SecRequestBodyNoFilesLimit  value in a configuration file, but that would get overwritten by updated firmware...

Is there a way to handle this within the WAF configuration?

Below is the log entry:

2015:12:10-20:29:34 ec2bfirewall reverseproxy: [Thu Dec 10 20:29:34.517448 2015] [security2:error] [pid 27646:tid 3803810672] [client 77.197.160.7] ModSecurity: Request body no files data length is larger than the configured limit (1048576).. Deny with code (413) [hostname "www.highcountry.com"] [uri "/CustomizeAttributeSelections.aspx"] [unique_id "VmngrQoAAAoAAGv@MEgAAABZ"]



This thread was automatically locked due to age.
Parents
  • I worked with Sophos support and they increased the internal limit that was preventing 1MB posts. The tech indicated that the limit may have an increased threshold in future releases.

    The exception idea would also work for us (a page specific exception) since this page is only accessed by logged-in users.
Reply
  • I worked with Sophos support and they increased the internal limit that was preventing 1MB posts. The tech indicated that the limit may have an increased threshold in future releases.

    The exception idea would also work for us (a page specific exception) since this page is only accessed by logged-in users.
Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?