Skip to main content
ppatel
Staff & Editor
Staff & Editor
November 29, 2021

Technical Tip: Behavior for 'action' value in WF for Local category

  • November 29, 2021
  • 0 replies
  • 769 views
Description

This article describes how the behavior of the 'action' value in web filter profile for Localy created categories. 

Scope

 

Solution

When a local category is created as follows: 

 

# config webfilter ftgd-local-cat  

     edit "custom1"  
            set id 140  
next
 
 

It can be applied with different actions in the web filter profile: 

 

# config webfilter profile  
    edit "teeest"  
# config ftgd-wf  
#  config filters  
    edit 1  
        set category 140  
           next  
      end  

end  
   next  
end
 
 
The category can have different 'action' values as follows.

Pay attention to 'allow' action which has different behavior in comparison to the regular Fortiguard categories: 

 

'Block' → Self explanatory, blocks all URL under this category.

 

'Authenticate' → Only available in proxy mode, will require client authentication in order to allow access to the category 

 

'Warning' → Displays warning page and 'proceed' button, note that a 'block' action will be logged in the logs in case of warning page. 

 

'Allow' → For local categories, allow means that the local category is allowed, but then the default FortiGuard category is applied and action is taken based on the URL fortiguard category.

 

'Monitor' → Allows the local category without further checking the Fortiguard category, also creates a log. 

 

In summary, for local category to fully bypass the original FortiGuard category, action 'monitor' have to be used. 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!