Configuring a URL Protection policy
URL protection policies can filter HTTP requests that match specific character strings and file extensions.
Before you begin:
- You must have Read-Write permission for Security settings.
After you have configured URL protection policies, you can select them in WAF profiles.
To configure a URL Protection policy:
- Go to Web Application Firewall > Access Protection.
- Click the URL Protection tab.
- Click Create New to display the configuration editor.
- Complete the configuration as described in URL Protection configuration.
- Save the configuration.
Settings | Guidelines |
---|---|
Name |
Configuration name. Valid characters are After you initially save the configuration, you cannot edit the name. |
URL Access Rule |
|
Full URL Pattern |
Matching string. Regular expressions are supported. |
Action |
Select the action profile that you want to apply. See Configuring WAF Action objects. The default is alert. |
Severity |
The default is low. |
Exception Name | Select an exception configuration object. Exceptions identify specific hosts or URL patterns that are not subject to processing by this rule. |
File Extension Rule |
|
File Extension Pattern |
Matching string. Regular expressions are supported. |
Action |
Select the action profile that you want to apply. See Configuring WAF Action objects. The default is alert. |
Severity |
The default is low. |
Exception Name | Select an exception configuration object. Exceptions identify specific hosts or URL patterns that are not subject to processing by this rule. |