Hi,
Our WebDevs have been having issues with getting hit with bots, and have determined that the bots never access a certain directory URL. All regular users hit this page with each page they load, I'm told.
Is there a method, possibly with user management, to mark a user as valid and allow me to block the rest?
Thanks!
Hi,
To restrict access to a webpage based on users hitting a certain directory first on FortiWeb, you can utilize the session management feature in the web protection profile. By configuring FortiWeb to track the session initiation and previous HTTP requests, you can ensure that users access the specific directory before accessing other pages. This method helps differentiate between legitimate users who follow the expected page order and potential bots that do not access the required directory, allowing you to block unauthorized access effectively.
Hi,
Would you be able to provide a few more details, or which submenu in Web Protection I should drill into? All the documentation for things like a "start page" doesn't seem to exist in 7.2.10. I've searched the Cookbook and haven't seen anything on how to mark a user once they hit a certain directory.
Thanks!
Hi @hcor87 ,
You know the users accessing the directory URL are valid, and the rest are invalid. Since the bots are causing the main issue and don’t access the directory URL, you can try the following approach:
Blacklist Bot IPs:
Bot Mitigation Policy with Rate Limiting:
If both these approaches don’t resolve the issue, please let me know so we can explore further options.
Thanks..!!
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1110 | |
759 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.