Question
(webfilter) What' s the difference between " passthrough" and " allowed" ?
FortiOS 5.0.4. I notice that webfilter entries for traffic which is not blocked by the webfilter shows up in the logs as " passthrough" . e.g.:
Oct 30 11:14:50 192.168.1.4 date=2013-10-30 time=11:14:50 devname=FG100D3 devid=FG100D3 logid=0315013317 type=utm subtype=webfilter eventtype=urlfilter level=notice vd=" root" policyid=30 identidx=0 sessionid=21843402 srcname=" MacBook-MacBook-Pro-de-B.local" osname=" Mac OS X" osversion=" 10.8.5" unauthuser=" bj" unauthusersource=" forticlient" srcip=192.168.32.8 srcport=60038 srcintf=" internal2" dstip=107.20.232.119 dstport=80 dstintf=" ISP-Colt" service=" http" hostname=" nagios.foo.net" profiletype=" Webfilter_Profile" profile=" default" status=" passthrough" reqtype=" referral" url=" /nagios3/images/comment.gif" sentbyte=633 rcvdbyte=187 msg=" URL has been visited" method=domain class=0 cat=255I re-checked just now, in the FortiOS GUI, all of the FortiGuard Categories (except for a very few which are " Block" ) are set to " Allow" . So why do I see " passthrough" instead of " allowed" in the logs? What would cause an " allowed" status to appear in the log? thanks,
