Skip to main content
usmansa1
Visitor III
December 6, 2025
Question

Webfilter not fully allow the website

  • December 6, 2025
  • 2 replies
  • 464 views

Hi, 

 

I blocked the Social Networking category on the firewall but attempted to exempt one specific site, facebook.com, by adding it to the static URL filter with the action set to Exempt. While this allowed the main site to load, certain elements such as logos and images were still blocked.

Upon reviewing the logs, I discovered that Facebook relies on additional content delivery domains (e.g., static.xx.fbcdn.net) to fully render the site. Since these dependent URLs were not included in the exemption, they were automatically blocked by the firewall. After explicitly allowing these domains, the website loaded correctly and became fully functional.

The challenge is that the firewall’s static URL filter does not automatically recognize or exempt dependent domains when the primary domain is allowed. Each supporting domain must be manually identified and added to the exemption list. Is there any way we can do this so the firewall automatically recognize it and allow ?

2 replies

funkylicious
SuperUser
SuperUser
December 6, 2025

hi,

usually this is how it works. you need to add/exempt each particular URI that the website has/needs to access to load different things.

you can try to exempt/allow in the webfilter a wildcard URL ( * ) with the Referrer facebook.com and/or www.facebook.com but you would need first to activate the option below for the field to be availabe in GUI:

 

config system setting

set gui-webfilter-advanced enable

end

"jack of all trades, master of none"
yderek
Staff
Staff
December 7, 2025

@usmansa1  Hi, Unfortunately, this is how category URL working, I understand that sometimes it's bit hard to find out why and need to find out the URL that redirect the site/sub-domains etc to add into the exemption list however there is not possible FortiGate can find this automaticlly