Does anyone have first hand experience with a WAF that did that?
In our case, we block the impossible combos and rate-limit the ones commonly used by botnets.
Blocking based on whether the UA has "Linux" in it is just dumb, though.
If you're behind a MITM web proxy at work, try going to Lowes.com - there's a chance you'll get blocked by their Akamai filter for putting headers back in the "wrong" (there is no wrong) way.
Old-school non-computerized discrimination (i.e. racism) work exactly the same way.
Especially if you’re facing an attack from a common UserAgent with all the other variables changing. And the admin likely thought “Linux users don’t use this service.”
You know what else is a terrible idea? Blocking IP ports in firewalls, or MAC based filtering, yet both of these are ubiquitous practices. Don't think something is not happening because you think is a bad idea. Other people, usually the ones in charge will often disagree.
It's like moving SSH to another port -- it won't stop anyone who knows what they're doing, but the majority of the bots that blindly connect to port 22 on every single host that has it open will be stopped by it.
That houseowner has probably set boobytraps etc.