FortiWeb
A FortiWeb can be configured to join a Security Fabric through the root or downstream FortiGate.
shafiq23
Staff
Staff
Article Id 307233
Description This article describes how to enable cookiesession1 secure flag attribute in the FortiWeb Cloud application.
Scope FortiWeb Cloud.
Solution

By default, cookiesession1 generated by FortiWeb Cloud is not set with secure flag attribute.

 

1.PNG

 

To prevent cookiesession1 value transmitted in clear text(HTTP), enable ‘Secure flag for internal Cookie’ under Network -> Endpoints -> expand SSL/TLS,  select Secure flag for internal Cookie button -> ON.

 

2.PNG

 

Clear saved cookies/cache if necessary and verify cookiesession1 secure flag.

 

3.PNG

 

For more information on endpoint settings, refer to the FortiWeb Cloud administration guide:
Endpoints 

Contributors