Evaluation License - Coming from Palo Alto - Issues with URL Filtering / Application Detection
Hi Everyone,
I'm having 10 years of experience with Palo Alto's. We make heavy use of their URL filtering and Application Detection.
In our environment it's not possible to decrypt any traffic, yet the Palo could block all URL's (based on SNI, certificate names etc) but here with the Fortigate Eval License it even refuses to block any webpage using the URL filtering - I've tried "youtube.com", whatsapp.com, facebook.com and none of these work and I'm refusing to believe that this isn't possible with a Forti without decryption.
What I've done:
1. Security Profiles -> Web Filter -> Create New -> Checked URL Filter (Static URL Filter) and I've choosen Wildcard, Block, Enable for *facebook.com* / *whatsapp.com* and "*youtube.com*"
2. I've made sure the Filter is set in "Flow Mode" and hit OK.
3. Created a "Firewall Policy" under "Policy & Objects" that includes this Filter:
Accept, All, All, All, Flow-Based, Web-Filter checked and choosen, SSL-Inspection left on "no-inspection" and asked it to log all sessions.
4. Taking a test-client, and trying to access the pages in question: All of them are accessible. (Sometimes facebook is blocked, even though in the traffic log its shown as "facebook.de" - which shouldnt be blocked in this example).
5. I've checked the traffic is hitting the correct policy (in eval mode you can only have 3 policies, so its not that hard)
6. I've checked the forward logs and I've seen IP's that resolved to whatsapp and others but were allowed ("UTM Allow" or "Accept").
I absolutely need this to work reliable on any webpage - without decryption. Am I missing something obvious?
On the Palo we use this a lot - for instance to create a pop up captive portal, but thats another topic I have yet to figure out here with the Fortigate.
I've done the same testing with using application filters and then using the applications and they too still worked. I did a cross-check against a palo with same configuration and it blocked it.
Thanks for helping out!
