Fortinet black logo

Administration Guide

What's new

What's new

Data Loss Prevention

The new FortiGuard Data Loss Prevention service is now supported on FortiWeb. It helps protect against data breaches by preventing sensitive data such as driver licenses, tax numbers, credit card numbers and others from leaving your network.

For more information, see Data Loss Prevention.

Security Fabric - FortiGSLB Connector

Fabric integration is supported between FortiWeb and FortiGSLB, allowing FortiWeb to publish host, domain name, and its paired public IP addresses directly to FortiGSLB. This functionality enables effective load balancing among multiple FortiWeb appliances that are securing the same domain name.

For more information, see FortiGSLB.

2023 OWASP API Security Top 10 Compliance

FortiWeb attack logs categorizations have been revised to align with the 2023 OWASP API Security Top 10, incorporating the latest updates relevant to the API security landscape.

New Enterprise Bundle License

The new Enterprise bundle is now available, incorporating both the Data Loss Prevention service and the FortiGuard Advanced Bot Protection solution.

Establishing trust with ADFS servers disabled by default

It is no longer required for FortiWeb to establish trust with ADFS servers when connecting with them.

For more information, see "enforce-trust-establishment" in config server-policy server-pool.

TCP Flood Prevention scan sequence change

The scan sequence of TCP Flood Prevention has been relocated from the top to after IP List. This adjustment ensures that trusted IP addresses can bypass the TCP Flood Prevention settings and be allowed through directly without verification.

For more information, see Sequence of scans.

Executing multiple URL rewriting actions simultaneously

It is now supported to perform more than one URL rewriting action simultaneously, such as inserting a custom header along with rewriting a header. To enable this functionality, ensure that Continue Executing the Next Rule is enabled in the URL Rewriting Policy.

For more information, see Rewriting & redirecting.

Bypassing AJAX check in MiTB protection

It's now supported to disable AJAX check in MiTB rules.

For more information, see Creating an MiTB protection rule.

Expiration time of cookiesession1 for client management

Now you can set the expiration time for the cookiesession1. The default expiration time is 365 days.

For more information, see "http-session-cookie" and "http-session-timeout" in waf web-protection-profile inline-protection.

Auto-deployment of FortiWeb Flex-VM license

We now support additional use cases for configuring the Flex-VM license token in pre-defined deployment templates. The Flex-VM license can be automatically imported during deployment in the following scenarios:

  • Deploying FortiWeb-VM in standalone mode on Google Cloud

  • Deploying FortiWeb-VM in HA mode on AWS, Azure, and Google Cloud

New platform: 400F

New models FortiWeb 400F has been introduced in this release.

What's new

Data Loss Prevention

The new FortiGuard Data Loss Prevention service is now supported on FortiWeb. It helps protect against data breaches by preventing sensitive data such as driver licenses, tax numbers, credit card numbers and others from leaving your network.

For more information, see Data Loss Prevention.

Security Fabric - FortiGSLB Connector

Fabric integration is supported between FortiWeb and FortiGSLB, allowing FortiWeb to publish host, domain name, and its paired public IP addresses directly to FortiGSLB. This functionality enables effective load balancing among multiple FortiWeb appliances that are securing the same domain name.

For more information, see FortiGSLB.

2023 OWASP API Security Top 10 Compliance

FortiWeb attack logs categorizations have been revised to align with the 2023 OWASP API Security Top 10, incorporating the latest updates relevant to the API security landscape.

New Enterprise Bundle License

The new Enterprise bundle is now available, incorporating both the Data Loss Prevention service and the FortiGuard Advanced Bot Protection solution.

Establishing trust with ADFS servers disabled by default

It is no longer required for FortiWeb to establish trust with ADFS servers when connecting with them.

For more information, see "enforce-trust-establishment" in config server-policy server-pool.

TCP Flood Prevention scan sequence change

The scan sequence of TCP Flood Prevention has been relocated from the top to after IP List. This adjustment ensures that trusted IP addresses can bypass the TCP Flood Prevention settings and be allowed through directly without verification.

For more information, see Sequence of scans.

Executing multiple URL rewriting actions simultaneously

It is now supported to perform more than one URL rewriting action simultaneously, such as inserting a custom header along with rewriting a header. To enable this functionality, ensure that Continue Executing the Next Rule is enabled in the URL Rewriting Policy.

For more information, see Rewriting & redirecting.

Bypassing AJAX check in MiTB protection

It's now supported to disable AJAX check in MiTB rules.

For more information, see Creating an MiTB protection rule.

Expiration time of cookiesession1 for client management

Now you can set the expiration time for the cookiesession1. The default expiration time is 365 days.

For more information, see "http-session-cookie" and "http-session-timeout" in waf web-protection-profile inline-protection.

Auto-deployment of FortiWeb Flex-VM license

We now support additional use cases for configuring the Flex-VM license token in pre-defined deployment templates. The Flex-VM license can be automatically imported during deployment in the following scenarios:

  • Deploying FortiWeb-VM in standalone mode on Google Cloud

  • Deploying FortiWeb-VM in HA mode on AWS, Azure, and Google Cloud

New platform: 400F

New models FortiWeb 400F has been introduced in this release.