I want to know how to block info.php or any other page through fortiweb. I created access rule and applied to web protection policy but does not seem to be working. Please see the screenshot below. Am I missing missing anything?
Tested in lab and the page has been blocked as expected.
Here is the config:
config waf url-access url-access-rule
edit "uar_test1"
set action alert_deny
config match-condition
edit 1
set reg-exp /info.php
next
end
next
end
config waf url-access url-access-policy
edit "uap_test1"
config rule
edit 1
set url-access-rule-name uar_test1
next
end
next
end
Hope it helps.
| User | Count |
|---|---|
| 2800 | |
| 1424 | |
| 812 | |
| 750 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.