Skip to main content

Generating FortiWeb WAF Rules from Invicti Standard

This document is for:
Invicti Standard

FortiWeb protects web applications from attacks that target known and unknown vulnerabilities. FortiWeb takes a comprehensive approach to protecting web applications, including IP reputation, DDoS protection, protocol validation, application attack signatures, bot mitigation, and more to defend your application against a wide range of threats, including the OWASP Top 10.

If you can't immediately fix all vulnerabilities that Invicti has detected, you can cover them up and defer fixing them until another time. This is achieved by exporting Invicti’s findings as rules for the FortiWeb WAF.

This topic explains how to configure Invicti Standard to send a detected vulnerability to FortiWeb WAF.

For further information, see Web Application Firewalls.

FortiWeb WAF Fields

FieldDescription
AddClick to add an integration.
DeleteClick to delete the integration and clear all fields.
Test SettingsClick to confirm that Invicti Standard can connect to the configured system.
ActionThis section contains general fields about the Send To Action.
Display NameThis is the name of the configuration that will be shown on menus.
MandatoryThis section contains fields that must be completed.
Server AddressThis is the name or IP address of the FortiWeb server, starting with http(s) and containing a port value. The default port value is 90.
UsernameThis is the username.
PasswordThis is the password of the user.
Policy NameThis is the policy name.

How to Configure FortiWeb WAF Rules in Invicti Standard

  1. Open Invicti Standard.
  2. From the Home tab on the ribbon, click Options. The Options dialog is displayed.
  3. Click Web Application Firewall.
FortiWeb WAF Settings in Invicti Standard
  1. From the Add dropdown, select FortiWeb. The FortiWeb fields are displayed.
FortiWeb WAF Settings in Invicti Standard
  1. In the Mandatory section, complete the connection details:
    • Server Address
    • Username
    • Password
    • Policy Name
  1. Click Test Settings to confirm that Invicti Standard can connect to the configured system and validate the configuration details. The WAF Settings Test dialog is displayed to confirm that the settings have been validated.
FortiWeb WAF Settings in Invicti Standard

How to Generate FortiWeb WAF Rules from Invicti Standard Scan Results

  1. Open Invicti Standard.
  2. From the ribbon, select the File tab. Local Scans are displayed. Double-click the relevant scan to display its results.
FortiWeb WAF Settings in Invicti Standard
  1. In the Issues panel, right click the vulnerability you want to export and select FortiWeb WAF Rules. (Alternatively, from the ribbon, click the Vulnerability tab, then FortiWeb WAF Rules.) A confirmation message and link is displayed at the bottom of the screen.
FortiWeb WAF Settings in Invicti Standard
  1. FortiWeb rule is created for the selected vulnerability message is displayed when the rule is created successfully.
  2. The rule is automatically created in the FortiWeb WAF. You can view it in FortiWeb WAF’s Custom Policy menu in the Custom Rules tab.
  3. To retest the vulnerability from the ribbon in Invicti Standard, click the Vulnerability tab, then Retest. If the WAF blocks the request, Invicti will display a message: Vulnerability seems to be fixed and removed from the report.
warning

Since FortiWeb does not provide an option for the request body, Invicti blocks the request method and URL. This causes non-vulnerable requests to be blocked.


Need help?

Invicti Support team is ready to provide you with technical help. Go to Help Center

Was this page useful?