Will fortigate WAF scan for XSS or SQL injections with a flow mode rules in newer versions?
For some reason the XSS or SQL injections are moved to a seperate WAF profile in Fortigate and not in the normal IPS functions but I saw the below article:


As I have test fortigate I confirmed with proxy mode rule and WAF feature enabled that basic web attacks are detected but in the newer trial versions proxy rules can't be used because of the RAM limit, so I can't test if now the newer versions can scan web traffic with a flow rule not only for antivirus.
If anyone can confirm if not now then in the future flow mode rules will support WAF profiles it will be great as at the moment even the waf profile is not visible under flow rules in the trial option!

I know that FortiWeb is a true WAF that has auto policy building with url, header and parameter learnings, API protections and discoveries, Javascript Bot Protections that use AI/ML but for basic security of a non impotant web servers fortigate could be enough.
