FortiAppSec Cloud
FortiAppSec Cloud delivers unified application security and performance with WAF, bot protection, GSLB, DDoS mitigation, threat analytics, and CDN.
shafiq23
Staff & Editor
Staff & Editor
Article Id 399920
Description This article describes how to verify the custom rule parameter filter configuration.
Scope FortiAppSec Cloud WAF.
Solution

Configuration:
To block specific HTTP URL parameter names and values.

 

1.png

 

 

Note:

The parameter name and value can be either plain and/or regular expression.

 

2.png

 

 

Steps to verify:

  1. Use curl or a browser to include the blocked parameter name or value in the HTTP request.

 

3.png

 

4.png

 

  1. The attack log will be generated in the FortiAppSec Cloud portal under Threat Analytics -> Attack Log.

 

5.png

 

Related article:
Custom Rule 

Contributors