Burp Suite User Forum

Create new post

Firewall gets activated when scanning

remco | Last updated: Aug 29, 2018 08:00AM UTC

Hi, When am scanning one of my websites everytime my firewall gets activated. I know i can ask my hosting support to disable the firewall but is there an other way. What helped before is when i change my vpn's ip but are there things i can adjust in the settings too? With kind regards, Remco

PortSwigger Agent | Last updated: Aug 29, 2018 10:12AM UTC

In general, it's not possible to use Scanner when the system has a tightly configured web application firewall (WAF) which is why we recommend asking the admin to whitelist you. You may be able to do this by reducing the rate at which Scanner sends requests. In Burp 1.7.x you can configure this in Scanner > Options > Active Scanning Engine. For example, reduce "Concurrent request limit" to 1 and introduce a "Throttle between requests". Because this will slow the scan you may also want to reconfigure Scanner to focus on high-risk issues that are likely to occur. There are also extensions in the BApp Store which help in some circumstances, such as Random IP Address Header.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.