Hi, many time, WAF (ver 5.60) block the POST to a particular page with many different signatures. This because on the raw body of the POST the customers send a xml within all type of char, code, url and other crap. This xml for the application isn't a problem, it's by developer's design.[&o] I don't want create a security hole and totally exclude the page from check signature process (with URL Access Rules), I want exclude from check process only the xml body. How I can do ?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
The only way that I found is, from Web Application > Know Attacks > Signatures, exclude signature by signature the Elements:
HOST = www.mysite.org as a string URI = /push/Service.asmx/SendXML as a string Parameter = BMS_XML as a string
but it's very long work.
Then can be better if we can exclude from all signatures the same parameters (BMS_XML)
I have similar question.
How is it possible to disable all signature checks for special parameter or url ?
I don't want to do it per signature!
This is very important feature! how come I cannot find any solution for it on the fortiweb!
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1705 | |
1093 | |
752 | |
446 | |
230 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.