Skip to main content
filiaks1
Explorer III
June 13, 2025
Solved

Will fortigate WAF scan for XSS or SQL injections with a flow mode rules in newer versions?

  • June 13, 2025
  • 4 replies
  • 990 views

For some reason the  XSS or SQL injections are moved to a seperate WAF profile in Fortigate and not in the normal IPS functions but I saw the below article:

 

Stream-based antivirus scanning for HTML and Javascript files | FortiGate / FortiOS 7.6.0 | Fortinet Document Library

 

 

Screenshot 2025-06-14 134457.png

 

Screenshot 2025-06-14 134634.png

 

 

 

As I have test fortigate I confirmed with proxy mode rule and WAF feature enabled that basic web attacks are detected but in the newer trial versions proxy rules can't be used because of the RAM limit, so I can't test if now the newer versions can scan web traffic with a flow rule not only for antivirus.

 

 

If anyone can confirm if not now then in the future flow mode rules will support WAF profiles it will be great as at the moment even the waf profile is not visible under flow rules in the trial option!

 

Screenshot 2025-06-14 135304.png

 

 

I know that FortiWeb is a true WAF that has auto policy building with url, header and parameter learnings, API protections and discoveries, Javascript Bot Protections that use AI/ML but for basic security of a non impotant web servers fortigate could be enough.

Best answer by sjoshi

While FortiOS has enhanced its antivirus engine to support stream-based scanning in flow mode—allowing partial buffering for HTML and JavaScript to reduce memory usage—this approach hasn't been extended to WAF signature scanning because WAF requires full HTTP session reconstruction to accurately analyze complex web traffic patterns, such as multipart forms, headers, and obfuscated attacks.

Which is why proxy based inspection is needed for WAF profile

4 replies

sjoshi
Staff
Staff
June 14, 2025

Hi @filiaks1 ,

 

Please refer below article:-

https://docs.fortinet.com/document/fortigate/7.6.3/administration-guide/64335/web-application-firewall

 

You can apply WAF profiles to firewall policies when the inspection mode is set to proxy-based.

 

So if the device does not support proxy for small end model then WAF can not be implemented as it required proxy based policy

Thanks, Salon
filiaks1
filiaks1Author
Explorer III
June 15, 2025

Thanks for confirming it. Still as mentioned in https://docs.fortinet.com/document/fortigate/7.6.0/new-features/518502/stream-based-antivirus-scanning-for-html-and-javascript-files in 7.X fortigate can scan javascript and html files in stream mode, so why this has not been used for scanning WAF signatures with a flow based rule is strange  as that is something I focused on.

sjoshi
Staff
sjoshiAnswer
Staff
June 15, 2025

While FortiOS has enhanced its antivirus engine to support stream-based scanning in flow mode—allowing partial buffering for HTML and JavaScript to reduce memory usage—this approach hasn't been extended to WAF signature scanning because WAF requires full HTTP session reconstruction to accurately analyze complex web traffic patterns, such as multipart forms, headers, and obfuscated attacks.

Which is why proxy based inspection is needed for WAF profile

Thanks, Salon
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.