The “Filter long URL strings” setting is part of the WordPress Tweaks module (which by the way is disabled by default).
According to the modules intro text:
These are advanced settings that may be utilized to further strengthen the security of your WordPress site.
Note: These settings are listed as advanced because they block common forms of attacks but they can also block legitimate plugins and themes that rely on the same techniques. When activating the settings below, we recommend enabling them one by one to test that everything on your site is still working as expected.
Remember, some of these settings might conflict with other plugins or themes, so test your site after enabling each setting.
So, if the (WordPress Tweaks) setting doesn’t play nice with your site’s (front and/or) backend don’t enable it. One of the strengths of the iTSec plugin is the simple fact that it offers you the flexibility to only enable the settings that work for your site.
To prevent any confusion, I’m not iThemes.