Fortinet 432 FortiWeb 5.0 Patch 6 Administration Guide
4. Configure these settings:
Setting
name
Description
Name Type a unique name that can be referenced in other parts of the
configuration. Do not use spaces or special characters. The maximum length
is 35 characters.
Host Status Enable if you want the hidden field rule to apply only to HTTP/HTTPS
requests for a specific web host. Also configure Host.
Host Select the name of a protected host that the Host: field of an HTTP request
must be in to match the hidden field rule.
This option is available only if Host Status is enabled.
Request
URL
Type the exact URL that contains the hidden input for which you want to
create a hidden field rule. This is usually a form that is visible to the person’s
web browser, not the CGI script or page that processes submitted forms.
The URL must begin with a slash ( / ). Do not include the web host name,
such as www.example.com. It is configured separately in the Host
drop-down list.