Skip to main content
yderek
Staff
Staff
February 6, 2025

Technical Tip: Deep seek is not blocking using webfilter static URL override

  • February 6, 2025
  • 0 replies
  • 6318 views
Description This article describes how to block Deepseek.com using a web filter.
Scope FortiGate.
Solution

Blocking deepseek.com can be done from Web Filter, using a static URL filter:

 

webfilter.jpg

 

The expected result will be:

 

result.jpg

 

However, in certain situations, organizations have allowed ISDB to object before deepseek.com blocking policy, for example, the screenshot below, that possibly causes deepseek.com not to be blocked properly, especially containing 'Cloudflare-CDN':

 

Screenshot 2025-02-06 141809.jpg

 

Cause:

When deepseek.com has been loaded, the first hop will be Cloudflare CDN.

 

2.jpg

 

Since Cloudflare CDN has been allowed in the policy before block policies hence deepseek.com will still be able to visit.

 

Solution:

Apply application control and deep inspection in ISDB policy.

 

5.jpg

 

Blocking deepseek.com will now, work properly. However, the FortiGate block page will display application control:

 

Screenshot 2025-02-06 142707.jpg

 

Related article:

Troubleshooting Tip: Why some blocked Websites are still accessible on FortiGate