DataPower中“Rejected by filter, soap fault sent”错误的触发场景咨询
Hey there! I’ve dealt with this exact DataPower error plenty of times, so let me walk you through the most common scenarios that trigger the Rejected by filter, soap fault sent message:
Request/Response Filter Policy Violations
This is the most frequent cause. DataPower’s filter policies (like those in XML Firewall or Multi-Protocol Gateway) are configured with allow/deny rules. If an incoming request hits a deny condition, the filter rejects it and sends a SOAP fault. For example:- A client IP is listed in your
IP Filterblacklist - The request’s SOAP Action isn’t included in your allowed actions list
- The request path doesn’t match the allowed resource patterns
- A client IP is listed in your
Schema Validation Failures
If you’ve enabled SOAP message schema validation, any request or response that doesn’t conform to your defined XSD schema will get rejected. Common triggers here include:- Missing required elements in the SOAP payload
- Data type mismatches (e.g., passing a string where an integer is required)
- Invalid enumeration values (e.g., a status field set to "INVALID" when only "ACTIVE"/"INACTIVE" are allowed)
WS-Security Policy Non-Compliance
When your service enforces WS-Security rules (like message signing, encryption, or UsernameToken authentication), requests that fail to meet these requirements are rejected. Examples:- No valid UsernameToken included in the request headers
- Message signature verification fails (invalid certificate or tampered content)
- Encrypted parts of the message can’t be decrypted with the configured keys
Custom Filter Logic Triggers
If you’ve added custom filtering via GatewayScript or XSLT, explicitly calling rejection APIs will trigger this error. For instance:- A GatewayScript snippet checks a request parameter and calls
dp.reject("Invalid order ID")when the ID is out of range - An XSLT stylesheet uses
dp:reject()to block requests with invalid payload content based on business rules
- A GatewayScript snippet checks a request parameter and calls
Rate Limiting/Throttling Breaches
When DataPower is configured with rate limits or throttling policies, requests that exceed the defined thresholds (e.g., too many requests per minute from a single client) are rejected. This is a common way to prevent abuse, but it will trigger the filter rejection error when limits are hit.Content-Based Filter Rejections
You might have content-specific filters that scan SOAP body fields for invalid values. For example:- A filter blocks requests where the order amount exceeds a configured maximum
- Requests containing restricted keywords in the payload are denied
内容的提问来源于stack exchange,提问作者Anu Manasa

