# Cors on aws ec2 Wowza version 4.6.0

**URL:** <https://community.wowza.com/t/cors-on-aws-ec2-wowza-version-4-6-0/48667>\
**Category:** Wowza Streaming Engine\
**Created:** [May 4, 2017, 7:48pm UTC](https://community.wowza.com/t/cors-on-aws-ec2-wowza-version-4-6-0/48667 "2017-05-04T19:48:15Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matt\_Wearing](https://avatars.discourse-cdn.com/v4/letter/m/3ab097/32.png) [@Matt\_Wearing](https://community.wowza.com/u/Matt_Wearing)\
**Post date:** [May 4, 2017, 7:48pm UTC](https://community.wowza.com/t/cors-on-aws-ec2-wowza-version-4-6-0/48667/1 "2017-05-04T19:48:15Z")

</div>

I am trying to change the value in the cors header in wowza. Currently it always comes back as \* no matter what the settings are on crossdomain.xml file or anywhere else. I am trying to restrict source domains with cors. Any advice?

---

<div class="post-metadata">

**Author:** ![system](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/system/32/447_2.png) [@system](https://community.wowza.com/u/system)\
**Post date:** [May 6, 2017, 11:58pm UTC](https://community.wowza.com/t/cors-on-aws-ec2-wowza-version-4-6-0/48667/2 "2017-05-06T23:58:09Z")

</div>

The crossdomain.xml file is for flash clients. You can configure CORS per [this](https://www.wowza.com/docs/how-to-enable-cross-origin-resource-sharing-cors-for-http-based-streams) article. If you upgraded from a version of Wowza Streaming Engine earlier than 4.4.0 then you will need to either add CORS by hand for that application or create a new application.

You can ban connections from referring domains as shown in [this](https://www.wowza.com/docs/how-to-control-access-to-your-application-by-checking-referer-domain-modulereferervalidate) article. You can also ban specific IP addresses by following the instructions in [this](https://www.wowza.com/docs/How-to-configure-security-using-Wowza-Streaming-Engine-Manager#client_restrictions_outgoing) article.
