Skip to main content
R00k13-NS
New Member
July 20, 2026
Question

How the Web Filter Works

  • July 20, 2026
  • 11 replies
  • 143 views

Hello,
I need to grant a specific USER/IP access to a specific path, which is as follows:

https://dl.k8s.io/release/v1.36.1/bin/windows/amd64/kubectl.exe

I usually use STATIC URL entries, where I typically set the FQDN to “SIMPLE” and “MONITOR” modes—meaning I just use dl.k8s.io—but in this case, I’m required to ensure that only the specified source has access to the URL I’ve provided.

Is there anything specific I need to do to achieve this?
What are the correct “Type” and “Action” to use in this scenario?
Do I need to take the “SSL/SSH Inspection” configuration into account?

Thanks for your feedback.

    11 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    July 20, 2026

    I’m assuming you’re using webfilter profiles with policies. 
    To allow a specif URL with HTTPS from a particular IP, you have to have a specific policy matching the source IP with the action:allow in the policy and place it above any other deny policies. Then in the policy, you want to have a webfilter profile that has a URL filter configured with the full URL:
    dl.k8s.io/release/v1.36.1/bin/windows/amd64/kubectl.exe
    and “Exempt” if you want to skip any other NGFW action against it.
    Then, of course you need to have some deny policies below the allow policy to block anything else you want to block from the source IP, or all others.
    You need to have at least “certificate-inspection” (prebuilt/unchangeable) inspection profile to filter HTTPS traffic. If you want to modify some behaviors with the certificate-inspection, you need to clone it first, then modify it, and then use it in the policy.

    Toshi

    R00k13-NS
    R00k13-NSAuthor
    New Member
    July 20, 2026

    I think my question hasn't been understood correctly.

    What I need is for the user/IP to access this URL “specifically”: https://dl.k8s.io/release/v1.36.1/bin/windows/amd64/kubectl.exe

    I don't want the user/IP to be able to access other directories on the FQDN.

    I understand that if I set the entry to dl.k8s.io and select “Simple” for Type and “Monitor” for Action, I’ll be allowing access to any part of the FQDN, but I want them to access only the section that ends in .exe.

    I hope my question is clear.

    Toshi_Esumi
    SuperUser
    SuperUser
    July 20, 2026

    That’s why I explained you had to have “deny” policy to block all others. If you want only this IP to access this URL but block all other URLs under “dl.k8s.io”, you can have this URL filter (host address only) to “Block” in the same webfilter profile right after the specific “Exempt” filter. Then you don’t need to have any additional deny policies for this source IP.

    “Monitor” would just monitor traffic to show in the log, It wouldn’t “Block” or “Exempt” traffic.

    Toshi

    Toshi_Esumi
    SuperUser
    SuperUser
    July 20, 2026

    “Simple” should be fine because you put the exact full URL into the URL filter entry. There is no wildcard ‘*’ or regex involved.

    Deep inspection is when you want the FGT to look into the content of traffic with IPS, Antivirus, Application control, and so on, because the packets are encrypted by TLS. And to implement that, you need to have a CA certificate and endpoint certificates singed by the CA and intall them to individual devices and the FGT. For URL filtering, it’s not necessary.

    Toshi

    R00k13-NS
    R00k13-NSAuthor
    New Member
    July 21, 2026

    Hello,

    Sorry for the delay in my response.
    So if I add the entry as 
    dl.k8s.io/release/v1.36.1/bin/windows/amd64/kubectl.exe .... would that be the same as if I configured it as dl.k8s.io   ???

    The attached images better illustrate my question.

    The goal is for the user to be able to access only that specific directory of the resource and not the entire portal itself.

    That’s why I want to make sure they can only access dl.k8s.io/release/v1.36.1/bin/windows/amd64/kubectl.exe

    If this is what I want, is it okay to configure it as “SIMPLE”?
    For this part, do I need to use “Deep Inspection,” or is “Certificate Inspection” sufficient?

    Toshi_Esumi
    SuperUser
    SuperUser
    July 21, 2026

    Monitor doesn’t block the other pages at the same host. You have to Block the rest like below. As I said before, “certificate-inspection” should be enough even HTTPS traffic. You can easily test it yourself using the same webfilter profile with a policy applied to your test device IP. That’s the ultimate way to confirm the behaviors of webfiltering. And, let us know if it behaves differently.

     

    Toshi 
     

     

    R00k13-NS
    R00k13-NSAuthor
    New Member
    July 24, 2026

    Hi, Toshi.
    The only thing I'd still need to keep in mind is that the “Exempt” action doesn't generate a log, right? Or does it?
    Because for troubleshooting situations, it's necessary to have logs that help identify problems.

    Toshi_Esumi
    SuperUser
    SuperUser
    July 24, 2026

    If “Exempt” doesn’t work for your needs, try “Monitor” instead. But be aware it would go through other protection profiles including the rest of the web filter profile, like web category filtering, which might block if the matching category is not allow.


    Again, test it with your test device to confirm the exact behavior. 

    Toshi

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!