Converting to a Fortigate firewall with user-assigned whitelists
I have a few whitelists of URLs that have been developed over time to match user needs.
I want to implement them on a new Fortigate 80_F 6.4.10.
My preferential approach is to have things as separate and distinct as possible. And, my notion is to have the firewall policies ordered so that the process will be fast and efficient.
I have firewall policies for:
Whitelist for all - so there are no names and Source is just "all". Uses a Static URL filter only.
Whitelist for buyers - trying to use a short list of names as Source. Not working yet but OK for this question.
Whitelist for others - same
DNS with DNS profile
HTTP-HTTPS with WEB, AV and APP profiles
Applications - with APP profile.
Social - with web profile
Catch-all - with web profiles
The idea is that these policies will either be acted on or skipped because they don't apply..
I wouldn't want one to overcome those remaining by letting unwanted traffic through.
Is that an issue and how to understand and deal with that?
