I wanted to block access to a specific URL when there is no 'referer' header.
I tried doing that using Advanced Protection->Custom policy and adding a rule with "URL" and "HTTP Header->Referer" as filters.
It seems I can't simulate a non existent referer header. I used an inverse match on .* and a match on .? as my regular expressions but I can't get this to work.
Any ideas on how to go about this?
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2677 | |
| 1412 | |
| 810 | |
| 703 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.