I have configured at least 5 different waf sites, and had to use different protection settings for each one. Some sites have been unable to use rigid filtering at all. I dont think form signing or cookie signing have ever worked for me. It has been a trial and error process each time. During the sales cycle, I came to expect WAF to be fully automatic, but that has not been my experience, and support has always acted as if trial-and-error is normal. Nothing was ever escalated to development.
To ensure trusted traffic, I configure WAF on an internal IP addtess, then edit my Hosts file to point a test pc at the waf site. I can use live log (on a second PC) to capture the traffic as it occurs, or download the logs after the fact.
Good information again, Doug.
When I said "developers," I was talking about the people coding the website behind WAF, not the Sophos devs.
Cheers - Bob