Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
asharaftab
New Contributor

Forwarding of Proxy Level Logs of FortiWAF

Dear Community,

I have few questions regarding FortiWAF.

 

1. How many Proxy modes FortiWAF Supports?

 

2. How to forward Proxy level logs of FortiWAF to SIEM?

 

Thank you.

Information Security Engineer
Information Security Engineer
1 REPLY 1
saneeshpv_FTNT

Hi,

 

FortiWeb supports multiple operation modes as below.

 

1.) Reverse Proxy

2.) Transparent proxy mode

3.) True Transparent proxy mode

4.) Offline Protection Mode

5.) WCCP Mode 

 

https://help.fortinet.com/fweb/552/Content/FortiWeb/fortiweb-admin/wccp.htm

https://help.fortinet.com/fweb/552/Content/FortiWeb/fortiweb-admin/operation_mode.htm 

 

For SIEM Logging you may configure a SIEM policy in the FortiWeb to define the IP address and port of SIEM server along with the log Format. Once the policy is configured, you may call it under log settings in the FortiWeb.

 

https://help.fortinet.com/fweb/560/Content/FortiWeb/fortiweb-admin/logging.htm#monitoring_2048514155... 

https://help.fortinet.com/fweb/560/Content/FortiWeb/fortiweb-admin/logging.htm#log_siem_policy 

https://docs.fortinet.com/document/fortiweb/7.2.3/administration-guide/303842/logging 

 

For HTTP traffic, please disable them if you are not planning to log your entire transactions locally as this might eat up your system resources. You may only enable them for remote logging or only enable attack logging as required. 

 

Regards,

 

 

 

 

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors