Skip to main content
dan_newcombe
New Member
August 14, 2018
Question

Forticlient webfilter profile ignored

  • August 14, 2018
  • 0 replies
  • 1981 views

I am trying to exempt a host from the web filtering. With FortiClient not running on the host I am able to get to the prohibited site. However, as soon as I enable Forticlient (with Web Filtering enabled), I can not reach the site, and I get the friendly blocked by forticlient page.

 

I looked in FortiClient monitor, and I see the desktop in there, with the correct IP address, Status is Registered - Online and the FortiClient Compliance Profile is set listed as IT Bypass.  When I go to Security Profiles, FortiClient Compliance Profiles and bring up the IT Bypass profile, I see that WebFilter is turned off, yet my Forticlient has it turned on.  If I turn Web filter on in the IT Bypass Profile, I then select WEB_FILTER_BYPASS for my Web Filter Profile. That profile has everything checked to allow.

 

However, in either of those two cases, the FortiClient does not allow me to the web site.

 

I cleared the logs, set them to debug, restared FortiClient and reconnected to the Fortigate, and no where in the logs is the word Bypass found, which I would assume it would log the profile it is sent.

So, by turning off web filter for my FortiClient profile, should that not disable the option on the client? And by assigning it a filter, should that not adjust the settings on the client?

 

The only thing that makes me wonder is that the client says "Compliance enforcement feature is not enabled on a FortiGate device".  Does that mean that no matter what I set, it's just not going to bother to tell the client to do anything?

 

Thanks.