Skip to main content
sebastan_bach
New Member
March 8, 2018
Question

no web filtering and no web-filtering logs in fortiOS 5.6 in flow mode

  • March 8, 2018
  • 14 replies
  • 21863 views

Hi, 

 

I am not sure if I am hitting a bug as always. I am trying to using basic url-filtering in the new flow mode in 5.6. Latest firmware GA version.

 

policy-1 allow service dns & icmp

policy-2 allow service http/https, no application, allow certain URL-categories (log)

policy-3 deny service http/https, no application, blocked certain categories (log)

policy-4 deny all

 

Under logs and reports in web-filter there is no logs. traffic is getting denied or permitted based on applications though I have not used them in the policy. 

 

does this thing really work as mentioned. 

 

has anyone got web-filtering to work in FortiOS 5.6 in flow mode. Please help.

 

Sebastan

    14 replies

    emnoc
    New Member
    March 8, 2018

    I believe you have a bug,  what model are you on? I found no  traffic logs for a FGT80C  but the local-in are working correcting. This was for memory or syslog logging. I will test your problem also and reported back tomorrow.

     

    Ken

     

    romanr
    New Member
    March 8, 2018

    sebastan_bach wrote:

    policy-1 allow service dns & icmp

    policy-2 allow service http/https, no application, allow certain URL-categories (log)

    policy-3 deny service http/https, no application, blocked certain categories (log)

    policy-4 deny all

    Hey,

     

    are you on NGFW firewall mode or on profile based firewall mode?

    - with profile based, this doesn't really make sense...

     

    Which FortiOS version are you running?

     

    Do you have full logging enabled - or only UTM logging?

    If you have only UTM logging, you need to set web-filter to monitor and not to allow, otherwise no log will be generated!

     

    Br,

    Roman

    sebastan_bach
    New Member
    March 8, 2018

    Hi, 

     

    Thanks for your quick reply. Sorry for the confusion. yes i am running in NGFW mode which default to flow mode. I am running FortiOS v5.6.3 build1547 (GA) . This is the latest firmware. All my rules are with logging enabled. how do I ensure that I have full logging enabled. Is there any command I can check on Cli. 

     

    Any help would be greatly appreciated. 

     

    Sebastan

    sebastan_bach
    New Member
    March 8, 2018

    I have logging enabled for all sessions and not just security events in the rules. 

     

    Sebastan

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.