Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rezafathi
Contributor II

Fortigate waf

Hi

 

We have a vip server facing outside of our company. I created a policy and enabled waf with all high severity enabled. When a user from outside submits a form, FGT waf recognizes it as sql injection extended and won't let the user submit the form and webpage crashes after. What should i do?

Reza F.
Reza F.
1 Solution
hbac

Hi @rezafathi,

 

There is no option to exempt IP address for WAF profile. You can create a new WAF profile and disable that signature. 

 

Regards, 

View solution in original post

3 REPLIES 3
abarushka
Staff
Staff

Hello,

 

You can find the forms below in order to contact specific teams regarding UTM databases:

 

https://www.fortiguard.com/contactus

 

However I cannot find WAF related team. Therefore, you may consider to use generic form in order to check whether it is false positive:

 

https://www.fortiguard.com/faq/general-contact

FortiGate
rezafathi

No i want to exclude a web server from extended sql injection. How can i do that?

Reza F.
Reza F.
hbac

Hi @rezafathi,

 

There is no option to exempt IP address for WAF profile. You can create a new WAF profile and disable that signature. 

 

Regards, 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors