If you believe that this is false positive or this header is required for proper work of your web server clients then just remove “Via” header name from “userdata_bl_headers” file.
I’ve been getting this error, too. My hosting clients pointed out that their users who were using AT&T data connections were not able to connect. I found this forum while googling the error message. I deleted the “via” header name from the “userdata_bl_headers” file, as suggested. It worked, but a few days later, the problem came back. Upon further investigation, I discovered the “via” header name entry was once again in the “userdata_bl_headers” file.
Why did this get put back in? Was it due to an apache update? When are you going to have a fix for this? Seems like a pretty big problem, considering how many folks are using mobile data connections these days.
So far so good no reported problems,all seems to be working fine now…
Edit :- Just as a side note all my Via errors being blocked was from AT&T data connections as well…Or at least mobile connections,same as ebrains…I will keep watching to see if these errors return and if the Via header get’s put back into the userdata_bl_headers" file after an update ect…
Funny thing is i started getting email alerts again tonight with the same /Via/ error messages…So i logged onto server and looked back into the userdata_bl_headers file and /Via/ had restored itself back into that file…
I think it because rules were updated yesterday.
Unfortunately we can’t preserve your changes If you use rules as cPanel vendor.
So if you want to save changes during update please use rules as cPanel plugin.
I did notice that there was an update and thought that must of been the reason behind the /Via/ restoring itself.
I do use cPanel vendor and not the plugin version and i’m very happy with that and i don’t really feel the need to change. I just removed /Via/ again and all’s working again no more hits…
Thanks again for the reply’s guy’s and keep up the great work.
I am still getting errors with rule 210740 COMODO WAF: HTTP header is restricted by policy. And the errors are mainly occurring with the AT&T wireless network (there may be other networks that don’t work too). Turning off the rule allows access to the sites.
I had the 1.63 update installed with the same AT&T errors with rule 210740. However, I installed the 1.64 update released today and now the rule and AT&T wireless no longer conflict.