Skip to main content
ISOffice
New Member
November 18, 2014
Solved

Is this normal??

  • November 18, 2014
  • 5 replies
  • 7153 views

Hi all,

 

I thought I would just share a recent experience we had with our FortiGate 100D Cluster (Active-Active), Version 5.2.1 Build 618.

 

I had created and applied a Web Filter Profile (let's call it Profile No1) to a particular group of users. I then cloned this Web Filter Profile, made a few changes to the cloned profile (imaginatively named Profile No2) and applied it to a second group of users.

My reason for two separate Web Filter Profiles was I wanted to impose slightly different Static URL Filters to each profile.

 

However, I noticed when I made a change to the Static URL Filter in either Web Filter Profile it immediately appeared in the other profile (wether I wanted it to or not). This had me confused as I imagined that the Web Filter Profiles were completely separate from each other.

 

I dug around in the configuration and found that in the config webfilter urlfilter section, a urlfilter called 'DefaultWebFilter' had been created. I also noticed that in the config webfilter profile section, sub-section config web was a setting, set urlfilter-table n (n = number assigned to DefaultWebFilter urlfilter).

 

I then was able to create a new webfilter urlfilter and assign the relevant Web Filter Profile to it and my problem disappeared.

 

I just wanted to know if anyone else has experienced this sort of behaviour and is it as a result of cloning existing profiles rather than creating them from scratch?

 

Hope this makes sense!!

 

Best regards,

 

JP

Best answer by rwpatterson

Sounds like a bug in the GUI. I would put in a ticket.

5 replies

rwpatterson
New Member
November 18, 2014

Sounds like a bug in the GUI. I would put in a ticket.

ISOffice
ISOfficeAuthor
New Member
November 18, 2014

Cheers Bob!! Might just do that.

 

I just thought it strange that the clone facility, while generally helpful, can cause some minor headaches. Best practice for now will be, create any new Web Filter policies from scratch. Wonder if it applies to Application Control, Intrusion Prevention etc. policies as well.

 

Thanks again,

 

JP

Dave_Hall
New Member
November 18, 2014

This also happens on 5.0.x (7/9).  But I personally do not see it as a bug, but more of an oversight on Fortinet's part (in not informing us) that the underlying URL filter list is not also cloned.  Checking the max value table, you are limited on the number of URL filter lists created vs Web filter profiles.  Although none of our Fortigates are nowhere near the max limit (web filter profiles vs URL filter lists), I can see someone running into this hard-coded limit on the mid-higher-end fgts.

Matthew_Mollenhauer
New Member
November 18, 2014

I'd agree with Dave in that this isn't so much a bug but rather an unintuitive UI.

 

When you break it down to the simplest terms the Web Filter Profile is simply an object as is the URL Filter. So you have Object A referencing Object B, cloning Object A will clone the reference not the Object referred to.

 

Consider when you clone an Address Group, do you expect that the Addresses that are members of the group to also be cloned?

 

Regards,

Matthew

ISOffice
ISOfficeAuthor
New Member
November 19, 2014

Hi Dave & Matthew,

 

Many thanks for your input. I agree that it's more of a minor nuisance than an actual bug. I'm just getting into the FortiGates and find that as each day goes by, I learn a little bit more. Very impressed overall with the product, just wanted to share the experience.

 

Best regards,

 

JP

ISOffice
ISOfficeAuthor
New Member
November 20, 2014

Hi All,

 

I submitted a ticket to FortiNet on this issue and their reply was....

 

"...managed to reproduce the same behavior and it seems that this is the expected behavior when cloning existing Web Filter profile. However we have already informed the development team about this and they are looking to make a change in the future release. Unfortunately, until then you will need to make the change from the CLI."

 

Best regards,

 

JP