diff --git a/content/controller/app-delivery/security/concepts/app-sec-default-policy-original.md b/content/controller/app-delivery/security/concepts/app-sec-default-policy-original.md
index 12105faae..5f57e3afc 100644
--- a/content/controller/app-delivery/security/concepts/app-sec-default-policy-original.md
+++ b/content/controller/app-delivery/security/concepts/app-sec-default-policy-original.md
@@ -1,7 +1,7 @@
---
description: Learn about the default protections provided by F5 NGINX Controller App
Security.
-docs: DOCS-479
+nd-docs: DOCS-479
title: Default WAF Policy
toc: true
weight: 200
@@ -34,7 +34,7 @@ The default policy for NGINX Controller App Security WAF includes these security
| Malformed cookie | Validates that the cookie format is RFC compliant. |
| Illegal status code | Responses in the 400–500 range -- except for `400`, `401`, `404`, `407`, `417`, `503` -- are rejected. |
| Request size exceeds the buffer | Requests that exceed the buffer size |
-| Maximum length for URL, header, query string, cookie, and POST data | URL length: 2048
Header length: 4096
Query string length: 2048
Cookie length: 4096
Post data length: 4096
{{< note >}} The whole request length is not checked. The entire request cannot exceed the maximum buffer size of 10 MB.{{< /note >}} |
+| Maximum length for URL, header, query string, cookie, and POST data | URL length: 2048
Header length: 4096
Query string length: 2048
Cookie length: 4096
Post data length: 4096
{{< call-out "note" >}} The whole request length is not checked. The entire request cannot exceed the maximum buffer size of 10 MB.{{< /call-out >}} |
| Disallowed file type extension | These file types are disallowed: