This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to tell if WAF config is working?

I have gone through the steps in the documentation for configuring WAF and the rule's traffic count increases accordingly when the web server is accessed.

However, I can't seem to be able to verify that it is actually being protected. Almost all protection and IPS settings are enabled and the filter strength is set to 4 (most restrictive). Yet when I make a directory traversal request (e.g. mysite.com/?q=../../etc/passwd) it doesn't get blocked.

How can I verify that the WAF is doing its job?



This thread was automatically locked due to age.
Parents
  • You should see successful and blocked requests within logviewer/WebServerProtection too.
    Requesting a /../../passwd resulting in a "WAF Anomaly"


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

Reply
  • You should see successful and blocked requests within logviewer/WebServerProtection too.
    Requesting a /../../passwd resulting in a "WAF Anomaly"


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

Children
No Data