Fortinet black logo

Handbook

Configuring an API Gateway policy

Configuring an API Gateway policy

An API gateway is an API management tool that sits between a client and a collection of backend services. It acts as a reverse proxy to accept all API calls and return the appropriate result.

API gateway on FortiADC provides the following functions:

  • API user management
  • API key verification
  • API access control
  • Rate limit control
  • Attach HTTP Header in API call

To configure an API Gateway Policy:

1. Go to Web Application Firewall > API Gateway.

2. Click the API Gateway Policy tab.

3. Click Create New to display the configuration editor and set up the configuration.

4. Save the configuration.

Settings

Guidelines

Name

Configuration name. Valid characters are A-Z, a-z, 0-9, _, and -. Whitespaces are not allowed. After you initially save the configuration, you cannot edit the name.

Rule Name

Specify one or more rules created in API Gateway Rule to be used in policy. The rules will be checked one by one from top to bottom until URL in request is matched to the Full URL Pattern in a rule.

Configuring an API Gateway policy

An API gateway is an API management tool that sits between a client and a collection of backend services. It acts as a reverse proxy to accept all API calls and return the appropriate result.

API gateway on FortiADC provides the following functions:

  • API user management
  • API key verification
  • API access control
  • Rate limit control
  • Attach HTTP Header in API call

To configure an API Gateway Policy:

1. Go to Web Application Firewall > API Gateway.

2. Click the API Gateway Policy tab.

3. Click Create New to display the configuration editor and set up the configuration.

4. Save the configuration.

Settings

Guidelines

Name

Configuration name. Valid characters are A-Z, a-z, 0-9, _, and -. Whitespaces are not allowed. After you initially save the configuration, you cannot edit the name.

Rule Name

Specify one or more rules created in API Gateway Rule to be used in policy. The rules will be checked one by one from top to bottom until URL in request is matched to the Full URL Pattern in a rule.