ApplicGate
(v13.0.9708.31578 started 2026-07-31 15:44:51 on VM2)

ADDH:param ... add http response headers.
For connections that terminate at the Application Gateway, e.g. manage, status, web, logon, OTP.

param is a list of http response headers or names of groups. The groups must be special groups where the names start with "H_".
The entries must be separated by |, e.g.
ADDH:"X-Frame-Options: DENY|X-Content-Type-Options: nosniff"
ADDH:H_1

A group can contain multiple response headers (each in a separate line, field IPranges).
Example:
 GroupName;IPranges                                                          ;Comment      ;eMail
H_1 ;Content-Security-Policy: script-src 'self' ;HTTP Headers ;
;X-Content-Type-Options: nosniff ; ;
;Strict-Transport-Security: max-age=31536000 \s includeSubDomains ; ;
Notes:
- In the groups file field IPranges any semicolon ";" must be masked using "\s".
- Any backslash "\" must be masked using "\\".
- When using the web interface to modify groups a semicolon and a backslash must be entered directly without masking.
- http headers containing a semicolon must be entered via a group because currently routing table entries do not allow additional semicolons.

If the keyword ADDH is not defined, following http response headers will be inserted automatically:
Content-Security-Policy: default-src 'self' 'unsafe-inline'; frame-ancestors 'none';
X-Content-Type-Options: nosniff
Notes:
- If the keyword ADDH is used, the headers set above will not be inserted automatically.
- For http header definitions see also Web Security and HTTP headers
- AS an additional option "Secure Transport Security" can be set using the keyword HSTS.
ApplicGate Logo  reinhold.leitner@applicgate.com (C) July 2026
www.applicgate.com