Created on
11-09-2020
07:04 AM
Edited on
06-11-2025
12:46 PM
By
Rudresh_Veerapp
Description
This article describes the procedure to identify the reason why traffic to specific URLs was blocked by WAF signatures when there is an event ID shown in Web Application Firewall logs as below and how to View WAF signature details with WAF’s event ID.
Scope
FortiGate.
Solution
The command below can be executed in CLI to check on signature details based on Web Application Firewall Event ID:
diag waf dump | grep –f 90300017
Note:
The CLI command 'diagnose waf dump' lists all the WAF signatures in FortiOS. It is only visible in CLI using this command, and not in the GUI.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.