FortiManager
FortiManager supports network operations use cases for centralized management, best practices compliance, and workflow automation to provide better protection against breaches.
Arif69
Staff
Staff
Article Id 413934
Description This article describes how to create a custom signature for WAF with a specific URL on FortiManager.
Scope FortiManager.
Solution

By default, Web Application Firewall is not available in Security Profiles. It needs to be enabled in Policy & Objects -> Security Profiles -> Tools -> Feature Visibility. Under Security Profiles, check the Web Application Firewall box.

 

In FortiManager, when navigating to Policy & Objects -> Security Profiles -> Web Application Firewall -> Default, there are no options to configure a custom signature with a specific URL:

 

chrome_PDKRPstdq1.png

 

To configure a custom signature in FortiManager, navigate to Policy & Objects -> Advanced -> CLI Configurations. In the search bar, search for WAF and expand. Under profile, select Create New and fill in the name:

 

chrome_JH3u0sDSps.png

 

Scroll downwards to 'custom-signature' and select Create New. In 'pattern' is where the custom URL can be defined:

 

chrome_zmj8pU8Ef3.png

 

After the custom signature is configured, save the configuration by selecting OK, then OK.

 

chrome_aYeFQj1ZDr.png

 

In Policy & Objects -> Security Profiles, the configured 'test1' can be seen:

 

chrome_SjTac1sFTT.png

 

However, the 'test1' WAF profile cannot be able to be pushed yet to the FortiGate. The profile will need to be used by any policies in the policy packages to ensure it can be pushed to the FortiGate.