Created on
03-28-2025
06:39 AM
Edited on
11-26-2025
10:26 PM
By
Jean-Philippe_P
| Description |
The article describes how to delete any details pointing to a web server name and type. |
| Scope |
FortiWeb. |
| Solution |
FortiWeb can be configured to remove an HTTP header by using a URL Rewriting Policy. In most cases, details about the server end are set on the headers like 'Server' and 'X-Powered-By', which can be configured on the URL Rewriting Rule as shown below:
The filter of the URL Rewriting Policy/Rule can be the HTTP Host (in this example, Server IP, but in general, a domain name can be used, depending on how the Web Server is accessed).
Notes:
CLI commands:
config waf url-rewrite url-rewrite-rule
Related document: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.