This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Test if WAF is working

Hello,

Can anyone recommend a 100% reliable test if WAF is actually working (especially the SQL-INJ/XSS features)? 

Firewall profile has form/url/cookie/xss/sql features enabled. I think I have configured the real webserver and virtual webserver correctly, but I don't know how to verify this.

Thank you!
Tim


This thread was automatically locked due to age.
Parents
  • actually possible as i did have a dnat going at the time..[[:)]]  however i'm having other issues that i will post on once i get a joomla 1.5 to either 1.6 conversion of convert said 1.5 to wordpress done..clients come first..the WAF is something for me..for now..[[:)]]

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

Reply
  • actually possible as i did have a dnat going at the time..[[:)]]  however i'm having other issues that i will post on once i get a joomla 1.5 to either 1.6 conversion of convert said 1.5 to wordpress done..clients come first..the WAF is something for me..for now..[[:)]]

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

Children
No Data