Skip to main content
Contributor
January 6, 2010
Question

How to filtering traffic if Using Explicit Proxy

  • January 6, 2010
  • 15 replies
  • 9880 views
Dear All, We use Fortigate unit as Explicit Proxy at our customer. But we have some problem when PC client used IP proxy fortigate the PC client can' t filtering by the unit, so the traffic going passtrough. Even if we not create firewall policy from internal port to internet port the PC Client traffic still going passtrough. How we filtering traffic from internal to internet if we using explicit proxy? Please suggest.

    15 replies

    Contributor
    January 6, 2010
    Are you using VDOMs on this Fortigate? If you are using the explicit proxy and trying to utilize a protection profile on that traffic, they must be in different VDOMs.
    flppds
    New Member
    January 7, 2010
    I have a similar problem: I tried to use 2 VDOM , VDOM1 to act as a explicit proxy and VDOM2 that apply Protection profiles. My problem is that I have different protection profiles for different user groups, and I cannot filter urls for example, because all requests are coming from the IP address of the explicit proxy. Now I am trying to use one VDOM1 in trasparent mode, to filter URL requests from users, then with an external cable connect to VDOM2 in NAT mode, that act as explicit proxy. I configured protocol recognition on port 8080 to use Fortinet Web Filtering with the url requests toward the proxy. Currently I am struggling to configure FSAE for correct user identification!
    Contributor
    January 22, 2010
    Thanks guys, I try to using 2 VDOMs and its work. Regards, Taufik
    flppds
    New Member
    April 7, 2010
    Hi, someone has tryed the new OS 4.0 MR2 that should fix this problem, and allow to do explicit web proxy and also web filtering, antivirus in just 1 VDOM?
    red_adair
    New Member
    April 8, 2010
    Yes, in 4.2 you get a " virtual Interface" and you basically write a FW Rule from Web-Proxy(IP-Range) -> WAN(IP-Range) Than you can apply AV or Web-Filter or user-auth to this Policy (No IPS or App-Ctrl yet). -R.
    ejhardin
    New Member
    April 8, 2010
    But the question is has anyone tried it... I' m on 4.2 and no it does not work. I have another ticket in with fortinet. (Mostly a bug... what a shock)
    Shahzadjeelal
    New Member
    April 9, 2010
    omeone has tryed the new OS 4.0 MR2 that should fix this problem
    Yes, i had tested this in my setup, its work very well with UTM features. But when i use identity based policy for web proxy interface. facing number of problem listed below. 1. The green color login page gone & its show NTLM type login page. 2. User monitoring not shows authenticated users. 3. Authentication timeout setting is not getting effected for wen proxy policy. mean very time when i open new browser its asking for authentication. 4. Frequently getting " 504 dns lookup failed" banner page. 5. IPS & App control UTM features are not applicable. 6. LDAP group extraction is not working with web proxy. Guys, Share your experience with MR2. Shahzad
    ejhardin
    New Member
    April 9, 2010
    How did you configure the web-proxy settings and the firewall settings? Also are you using switch-interface. I have configured the web-proxy and know that it is working because if I enable the allow default firewall policy then I' m able to access the internet but this settings does not apply any utm protection. I have created a policy with the web-proxy as the source. It seems like the web proxy is not reading the firewall policy and I believe that it has to do with the switch-interface settings. Any ideas?
    Shahzadjeelal
    New Member
    April 10, 2010
    configuration steps: 1. enable web proxy on interface 2. go to web proxy tab & configure required settings. (Deny) Default Firewall Policy Action. 3. Create policy between Web Proxy (Logical interface > external interface. Enable identity based policy session base not IP based. Note: In my setup , i was using fortigate 310-B, which is by default running on interface mode only.
    Natanael
    New Member
    April 10, 2010
    Hi, This Explicit Proxy setting with Control for users only Work with 2 VDOMs for FortiOS 4.0 MR1, but in FortiOS 4.0 MR2, we can use Explicit Proxy an Control in same VDOM. Here there is a Lab procedure for Explicit Proxy an Contro for Users in 4.0 MR2. http://www.soportejm.com.sv/kb/index.php/article/fg-proxy-explicito Regard Natanael Calderón