Skip to main content
fred339
Explorer III
October 13, 2022
Question

Converting to a Fortigate firewall with user-assigned whitelists

  • October 13, 2022
  • 12 replies
  • 4795 views

I have a few whitelists of URLs that have been developed over time to match user needs.

I want to implement them on a new Fortigate 80_F 6.4.10.

My preferential approach is to have things as separate and distinct as possible.  And, my notion is to have the firewall policies ordered so that the process will be fast and efficient.

I have firewall policies for:

Whitelist for all - so there are no names and Source is just "all".  Uses a Static URL filter only.

Whitelist for buyers - trying to use a short list of names as Source.  Not working yet but OK for this question.

Whitelist for others - same

DNS with DNS profile

HTTP-HTTPS with WEB, AV and APP profiles

Applications - with APP profile.

Social - with web profile

Catch-all - with web profiles

 

The idea is that these policies will either be acted on or skipped because they don't apply..

I wouldn't want one to overcome those remaining by letting unwanted traffic through.

Is that an issue and how to understand and deal with that?

 

 

12 replies

gfleming
Staff
Staff
October 13, 2022

If you are using FSSO/user sources in your policies then the only policies that will apply will be the ones that those users are authorize for (based on group membership most likely). 

 

For any policies that are not FSSO or based on user auth you just follow the standard approach of most specific to least specific.

fred339
fred339Author
Explorer III
October 13, 2022

Graham,

Thank you!

That's what I'm used to and what I'm trying to do.  

Where I'm the most unsure is seeing the combination of category filtering AND URL filtering in the same policy.  I can choose to NOT use category filtering when I'm going to apply a whitelist in a policy.  Is that good practice?  It appeals to me in the sense of keeping things separate and distinct.  That being the case, it would seem less confusing.

gfleming
Staff
Staff
October 13, 2022

It's totally up to you. Personally I like using the FortiGuard categories as it's a lot less work maintaining a whitelist. If you have a large list of URLs you may also want to look at using a threat feed remote URL filter category: https://docs.fortinet.com/document/fortigate/7.2.2/administration-guide/009463/threat-feeds

fred339
fred339Author
Explorer III
October 19, 2022

@gfleming :  OK well that makes it clear enough.  So, what is the difference between one of these web rating overrides and a Static URL filter?  I was given the impression (separately) that a static URL filter combined with a category filter would "let anyone through" which I didn't fully understand.  Thus this question was posted.

gfleming
Staff
Staff
October 20, 2022

There's no real difference. Both can accomplish the same thing. From my perspective given what you are trying to accomplish I would think using overrides would be simpler. However, yes you can also use URL filter to exempt these sites to whitelist them as well. The choice is yours... I suggest you review the docs and figure out which one makes most sense for you based on what you assume to be your configuraiton and workload in implementing it:

https://docs.fortinet.com/document/fortigate/7.2.2/administration-guide/615462/url-filter

 

https://docs.fortinet.com/document/fortigate/7.2.2/administration-guide/122974/web-rating-override

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!