FortiWeb Appliances
FortiDAST integration with FortiWeb appliances deployed on-premises offers two options for generating WAF rules.
-
Automatic WAF rule generation
-
In the WAF Configuration page, specify the FortiWeb appliance details like IP address, username, password, and VDOM name.
-
Upon completion of the scan, an XML file containing identified vulnerabilities is generated.
-
FortiWeb appliance automatically parses the XML and dynamically creates corresponding WAF rules based on the configured actions and supported vulnerabilities.
-
-
Manual WAF rule generation
-
Navigate to Scans Overview > Summary > Overview and download the report in XML format. See Exporting Scan Result to FortiWeb WAF.
-
You can manually upload the downloaded XML report to FortiWeb appliance to create WAF rules based on the reported vulnerabilities.
-
Note: Automatic WAF rule generation is currently only supported for FortiWeb appliances deployed on-premises.