Skip to main content
gsharma
Staff
Staff
March 21, 2025

Technical Tip: How to block 'http_agent="Custom-AsyncHttpClient"' on FortiWebCloud

  • March 21, 2025
  • 0 replies
  • 479 views
Description This article explains how to block 'http_agent="Custom-AsyncHttpClient"'.
Scope FortiAppsec Cloud.
Solution

FortiAppSec Cloud can be used to block the traffic coming from 'http_agent="Custom-AsyncHttpClient"'.  For that Custom Rule can be created.

 

To create a Custom Rule for blocking 'http_agent="Custom-AsyncHttpClient"'. 

  1.  Open the application in which 'Custom-AsyncHttpClient' needs to be blocked.
  2. On the left Pan, go to Advanced Application -> Custom Rule.

    clcs1.JPG

     



  3. Create a Rule, give the name, and setthe  operation as either Alert/Deny or Period Block.
  4. After the rule is made, it is necessary to add Filter, so below the rule select Add Filter ->  Filter-type: HTTP Header -> Header Name: User-Agent.
  5. Inside the Value Pattern, fill the RegEx code as '[Cc]ustom-[Aa]sync[Hh]ttp[Cc]lient' (this can be modified based on the http_agent in the traffic logs) select OK, and select Save Filter.

    csrul1.JPG

     

     

Note:

If the issue is not resolved, reach out to the support helpline with the required config and logs. The Regex code used above might need to be modified based on the requirement. 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.