Skip to main content
Loky_40NT
Staff
Staff
October 31, 2024

Technical Tip: Content-Security-Policy(CSP) header on Block Pages for websites hosted on FortiWeb

  • October 31, 2024
  • 0 replies
  • 1069 views

Description

This article explains how to retrieve the Content-Security-Policy (CSP) header on block pages in FortiWeb.

Scope

FortiWeb v7.4.5, v7.6.1 and higher, v8.x.

Solution

Prerequisite.

Configure/create an HTTP Header Security Policy:

  1. On version 7.x, navigate to Web Protection -> Advanced Protection -> HTTP Header Security -> HTTP Header Security Policy and select + Create New.


668c7927.png


  • On version 8.x, navigate to Web Protection -> Client Side Security -> HTTP Header Security -> HTTP Header Security Policy and select + Create New.


68732c9a.png


  1. Enter a name for the new HTTP Header Security Policy and select 'OK'. To add a Content Security Policy (CSP) header, select + Create New.


7636581c.png


  1. Choose Content-Security-Policy as the header type. Set the header value to 'default-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:' or another value appropriate to the application's requirements. Select 'Validate' to ensure that the value entered is valid and then Select 'OK'.


5ab96ed4.png


The view is different on version 8.x but the settings remain the same:

c31d58e4.png


  1. Assign this new HTTP Header Security Policy with the Content-Security-Policy header to the Web Protection Profile that is applied to the protected web server policy.


e40401a7.png

 
With this configuration, the Content-Security-Policy (CSP) header will be included on both block and allow pages in FortiWeb.

Note:

In FortiWeb versions before v7.4.5 and v7.6.1, the CSP header was only applied to allowed traffic and not on block pages.


Related document:

HTTP Security Headers

    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!