Skip to main content
Goatrman
New Member
March 16, 2018
Solved

Issue blocking Youtube

  • March 16, 2018
  • 4 replies
  • 39904 views

Fortigate 80C Firmware 5.0

 

I am having an issue trying to block youtube.com. 

[ul]
  • I have the web-filter subscription.
  • I have edited the Web filter profile to block all "Bandwidth consuming" sites (Streaming ect)
  • Enabled website filter, *Youtube.com / Wildcard / Block / Enable. [/ul][ul]
  • I have added Web filter to my policy for my network. (Internal 2 - WAN 1) 
  • I rebooted the Fortigate to ensure all sessions were stopped, so this could take effect. [/ul]

    People on the network are still accessing Youtube.

     

    Still no luck, Any assistance would be appreciated. 

     

    • Best answer by Dave_Hall

      "Deep packet" inspection needs to be enable on the firewall policy covering "web traffic" - otherwise "blocking" just by web/URL filter (via security certificate inspection) may/will not work (because youtube uses Google's *.wildcard security certificate).  

       

      If Application Control does not work and you can not use "Deep packet" inspection then you could try blocking direct access to the main fqdn addresses via firewall polices - IMO it's "ugly" but does work to a certain extent. YMMV.

       

      Another option would be to use DNS web filtering.

      4 replies

      Toshi_Esumi
      SuperUser
      SuperUser
      March 16, 2018

      URL based blocking probably wouldn't work well. Try using Application Control instead like below. Also we have Application Control Forum about it where you can search more.

      http://cookbook.fortinet....-youtube-applications/

      Dave_Hall
      Dave_HallAnswer
      New Member
      March 16, 2018

      "Deep packet" inspection needs to be enable on the firewall policy covering "web traffic" - otherwise "blocking" just by web/URL filter (via security certificate inspection) may/will not work (because youtube uses Google's *.wildcard security certificate).  

       

      If Application Control does not work and you can not use "Deep packet" inspection then you could try blocking direct access to the main fqdn addresses via firewall polices - IMO it's "ugly" but does work to a certain extent. YMMV.

       

      Another option would be to use DNS web filtering.

      Goatrman
      GoatrmanAuthor
      New Member
      March 24, 2018

      Toshi and Dave, Thanks for the responses, I will try these suggestions and report back with my results.

      Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
      Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!