Dear Community,
I have few questions regarding FortiWAF.
1. How many Proxy modes FortiWAF Supports?
2. How to forward Proxy level logs of FortiWAF to SIEM?
Thank you.
Hi,
FortiWeb supports multiple operation modes as below.
1.) Reverse Proxy
2.) Transparent proxy mode
3.) True Transparent proxy mode
4.) Offline Protection Mode
5.) WCCP Mode
https://help.fortinet.com/fweb/552/Content/FortiWeb/fortiweb-admin/wccp.htm
https://help.fortinet.com/fweb/552/Content/FortiWeb/fortiweb-admin/operation_mode.htm
For SIEM Logging you may configure a SIEM policy in the FortiWeb to define the IP address and port of SIEM server along with the log Format. Once the policy is configured, you may call it under log settings in the FortiWeb.
https://help.fortinet.com/fweb/560/Content/FortiWeb/fortiweb-admin/logging.htm#log_siem_policy
https://docs.fortinet.com/document/fortiweb/7.2.3/administration-guide/303842/logging
For HTTP traffic, please disable them if you are not planning to log your entire transactions locally as this might eat up your system resources. You may only enable them for remote logging or only enable attack logging as required.
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.