Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to tell if WAF config is working?

I have gone through the steps in the documentation for configuring WAF and the rule's traffic count increases accordingly when the web server is accessed.

However, I can't seem to be able to verify that it is actually being protected. Almost all protection and IPS settings are enabled and the filter strength is set to 4 (most restrictive). Yet when I make a directory traversal request (e.g. mysite.com/?q=../../etc/passwd) it doesn't get blocked.

How can I verify that the WAF is doing its job?



This thread was automatically locked due to age.
Parents Reply Children
No Data