Technical Tip: Unable to find Web Application Firewall (WAF) profile in the security policy or in the GUI
Description
This article describes how to enable the Web Application Profile option in the GUI and use it in the policy.
Scope
FortiGate.
Solution
- Make sure the NGFW mode is in the profile-based mode, this feature is not supported in the policy-based mode.
- This feature is not supported in the models with less than 2GB RAM starting from the Forti OS firmware version 7.4.4.
- In the GUI, go to System -> Feature Visibility -> Enable the Web Application Firewall option and select Apply.
- If the Web Application Firewall option is greyed out then refer to the below article:
Technical Tip: How to enable WAF in policy
If not, continue on step 5.

Once it is enabled, WAF profiles can be configured under the security profiles.
- To Apply the WAF profile, make sure the inspection mode is set to the proxy-based inspection in the policy.

Web Application Firewall profile is only supported in the proxy-based inspection not in the flow-based inspection.
