Technical Tip: Category Filtering missing under Web Filter security profile when in NGFW policy-based mode
| Description | This article describes a known-behavior where FortiGuard Category-Based Filter option is missing in the Web Filter profile while the FortiGate is in NGFW policy-based mode. |
| Scope | FortiGate, NGFW policy-based mode, Web Filter |
| Solution | When attempting to configure a Web Filter profile on the FortiGate, administrators may find that the FortiGuard Category-Based Filter section is not available to be configured:
This is an expected behavior if the FortiGate/VDOM is operating in NGFW policy-based mode, as the URL category filtering functionality is moved out of the Web Filter profile and is instead configured directly in the Security Policy section. For more information on URL category filtering and Web Filter profiles in NGFW policy-based mode, refer to the following KB articles: Technical Tip: How to block URL Category and Application in NGFW policy-based mode Technical Tip: Web filter profiles in NGFW policy mode
To determine if the FortiGate/VDOM is operating in NGFW mode, check the following locations:
FortiGate (NGFW) # show full-configuration system settings | grep ngfw-mode set ngfw-mode policy-based
FortiGate (NGFW) # get system settings | grep ngfw-mode
Note: Changing the NGFW mode back from policy-based to profile-based will move FortiGuard Category-Based filtering back into the Web Filter profile, but it will also remove all existing policies (SSL Inspection & Authentication Policy, Security Policy, Central SNAT), so think carefully before changing an existing FortiGate/VDOM from one NGFW mode to another.
If the mode is changed back to NGFW profile-based mode, FortiGuard Category-Based Filtering will become available in the Web Filter profile:
Related Documents: Technical Tip: NGFW policy-based mode Resource List Technical Tip: Profile-based policies vs Policy-based policies |





