Skip to main content
Nihas
New Member
October 23, 2015
Question

URL Filtering _ Custom URL _ Basic Doubts.

  • October 23, 2015
  • 1 reply
  • 5000 views

Hi Friends,

Can you please help me to  understand how the custom URL works in fortigate?

I have a scenario like below , please help.

 

1.  https://prod.company.com/sitea  --- Allow   ( IP 201.201.201.201)

2.   http://dev.company.com:9898/sitea -- Allow 

( Only these 2 above sites needs to be allowed from the highly protected network)

Rest all including ,

3. https://prod.company.com          ( IP 201.201.201.201)

4. http://company.com 

5. http://dev.company.com 

6.  "*.company.com" should be blocked at our end. But the challenge here is both allow and deny URL's having same IP. In such scenario how does a brilliant Fortigate take a decision? 

 

Questions..

1. Basically how does a fortigate determines a http & https traffic belongs to a particular category / URL filter?

1.a  - Which field of packets does it inspect to get the details ( CN / SNI / ?? )

 

2. How can I create a URL filtering profile for the above scenario? Will the below work?

            https://prod.company.com/sitea  -- simple - allow

            http://dev.company.com:9898/sitea --- simple --allow

             *.*  -- wildcard -- Block

 

Thank You in advance.. :)

Nihas

 

    1 reply

    Nihas
    NihasAuthor
    New Member
    October 23, 2015

     

     

    1. Does Fortigate send the request to Fortigurad service for each http & https request?

    2. Which part of packet does it consider for the inspection ? CN or http header or SNI or IP ?

    3. How does it take a decision if both allow & deny URL's are configured in a same IP?

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!