Skip to main content
unknown1020
Explorer III
January 30, 2024
Question

WAF profile in fortigate

  • January 30, 2024
  • 4 replies
  • 1909 views

Friends, a question, I enabled the WAF profile in monitoring mode in a publication that I created in my firewall. However, it doesn't show me logs. In my FAZ it doesn't show me the WAF option in security either.
Is there a command to enable log sending? Or is it normal that it doesn't show me logs?

4 replies

mpftnt
Staff
Staff
January 31, 2024
unknown1020
Explorer III
January 31, 2024

Hello, thanks for the link, checking the configuration in the CLI of my firewall, it does not mention "log disable".
Do I have to run " set log enable " in all main config?

This is what it shows me on my firewall:
config signature
config main-class 10000000
set status enable
end
config main-class 20000000
set status enable
end
config main-class 30000000
set status enable
set severity high
end
config main-class 40000000
set status enable
end
config main-class 50000000
set status enable
set severity high
end
config main-class 60000000
set status enable
end
config main-class 70000000
set status enable
set severity high
end
config main-class 80000000
set status enable
set severity low
end

AEK
SuperUser
SuperUser
January 31, 2024

Did you simulate an attack and didn't get WAF log? I guess there is no log if there is no detected attack.

AEK
rosatechnocrat
Explorer III
January 31, 2024

For an attack log to be generated it has to match a attack signature. 

 

You can try simulating a attack or an basic SQL injection which should match signature. 

Subscribe "ROSA Technocrat" on Youtube for Fortinet Videos and Troubleshooting https://www.youtube.com/@rosatechnocrat
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!