Policy and protection profile behavior and supported features varies by the operation mode. (See also Supported features in each operation mode.)
The WCCP operation mode is similar to True Transparent Proxy, except web servers see the FortiWeb network interface IP address and not the IP address of the client.
The way that FortiWeb determines which policy to apply to a connection varies by operation mode. The appliance applies only one policy to each connection.
If a TCP connection does not match any of the policies, FortiWeb either refuses the connection (if it is operating in reverse proxy mode) or denies the connection (if it is operating in other operation modes). Even if the TCP connection has a matching policy and is allowed, subsequently, if the HTTP/HTTPS request is not allowed by the policy’s profiles, it is considered to be in violation of the policy and the client may be blocked at the application (request) level or connection level, depending on the Action that you configure.
Policies are not applied while they are disabled. See Enabling or disabling a policy.