Skip to main content
Contributor
March 23, 2006
Question

Blocked sites getting through Web Filter

  • March 23, 2006
  • 2 replies
  • 5990 views
Greetings, In reviewing my web filtering report of blocked and allowed sites, I have noticed that the categories that I have set to blocked still get through. For example: Category Allowed Blocked Monitored Pornography 752 8100 15927 Adult Materials 264 4382 35383 Spyware 2320 19482 223801 Is this because I have the protection profile set to Allow websites when a rating error occurs? Are there really that many rating error? What constitutes a rating error? Thanks, Steve

    2 replies

    UkWizard
    New Member
    March 24, 2006
    it could be that setting if all lookups are failing, like if the web category licensing isnt valid (check its valid and enabled under the category block menu) or web access is being denied (like if its in transparent mode, behind another firewall) or the protection profile isnt turned on the rule thats being hit in the policies. maybe your web traffic is hitting a different rule than you think it is.
    Contributor
    April 5, 2006
    Hi UkWizard, I know that the web filtering license is valid. FortiGuard Status: Available [check status] License Type: Contract Expiration: Fri Mar 14 19:00:00 2008 After you posted this I checked all my rules and protection profiles again. I reset the content summary on the SYSTEM > STATUS page. That cleared all the info on the WEB FILTER > CATEGORY BLOCK > REPORT page. I did have one rule that did not have web filtering enabled on the protection profile. However, the lower rule was using a different protection profile than the one I was looking at on the WEB FILTERING > CATEGORY BLOCK > REPORTS. Basically I have two rules that allow port 80 and 443 traffic outside of the organization. One Strictly for Outbound Web traffic and a lower rule in the tree that allows port 80 and 443 traffic. I changed the lower rules protection policy to match the Outbound web traffic rule as far as categories that are monitored, blocked and allowed. Checked the WEB FILTERING > CATEGORY BLOCK > REPORTS page today and there are a number of sites that are listed as ALLOWED for categories that I specifically block. Pornography Allowed - 757 Blocked - 8598 Monitored - 15927 Spyware Allowed - 2322 Blocked - 19633 Monitored - 223801 On the Protection profile I have the following checked: Enable category block (HTTP only) Provide details for blocked HTTP 4xx and 5xx errors (HTTP only) Rate images by URL (blocked images will be replaced with blanks) (HTTP only) Allow websites when a rating error occurs (HTTP only) What am I missing? Is it the " Allow websites when a rating error occurs" that is causing the sites to get through? Thanks, Steve
    Contributor
    April 5, 2006
    Forgot to mention that the firewalls are in NAT mode and not behind any other firewalls. They are behind load balancers for multiple internet connections. If that matters. Steve
    Andrew_Badge
    New Member
    April 4, 2006
    Hi Steve, My response my be obvious or basic, so please ignore if you know this already. The forigate only scan specific ports for AV and content filtering (ie. port 80) out of the box. You can add other ports to scan eg. if you have proxy server in the DMZ (port 8080?). This is a CLI command only. This allows you to configure certain groups of users to have different protection profiles group A using profile A (Client -> DMZ) group B using profile B (Client -> DMZ) No filtering (DMZ -> Internet) maybe a waste of your time, but it wasn' t obvious to me initally (maybe i shouldn' t skim the manuals). Andrew
    Contributor
    April 5, 2006
    Hi Andrew, Thanks. I was not aware of that. However, I don' t think it will matter as we only allow port 80 and 443 out for web traffic. Steve
    abelio
    SuperUser
    SuperUser
    April 5, 2006
    Checked the WEB FILTERING > CATEGORY BLOCK > REPORTS page today and there are a number of sites that are listed as ALLOWED for categories that I specifically block
    Hi Steve, you can check if sites you hope or suppose be blocked for Fortiguard webfilter looking up in http://www.fortinet.com/FortiGuardCenter/webfiltering.html I found it some surprises there. regards,