Skip to main content
Headspinning
New Member
August 10, 2017
Question

Webfiltering Fortiguard query - hostname only or full url path ?

  • August 10, 2017
  • 4 replies
  • 11913 views

Hi,     I wondering if someone can advise me when Fortigate webfilter perform category check with Fortiguard server, it is just submit the hostname or the full URL path.   For example, when a user access to [link]http://www.aaa.com/bbb/ccc.js,[/link] is the fortigate going to query the Fortiguard server with www.aaa.com or www.aaa.com/bbb/ccc.js ? Regards Kevin

    4 replies

    oheigl
    New Member
    August 10, 2017

    I guess this will be helpful to explain the different situations, it's taken from the FortiOS Handbook 5.4.4

     

    Scenario 1: The configuration of the domain name overrides the configuration for the subdirectory. Depending on the URL specified or other aspects of configuration, the configuration of a local or custom category may not take effect. Consider a scenario where you have defined:

    [ul]
  • example.com – local rating as “category 1”, action set to Block
  • example.com/subdirectory – local rating as “category 2”, action set to Monitor
  • example.com/subdirectory/page.html – local rating as “category 3”, action set to Warning.[/ul]

    If a user browses to “example.com", access will be blocked. If a user browses to example.com/subdirectory, access will also be blocked,even though that address was configured to be part of category2. The configuration of the domain name overrides the configuration for the subdirectory. However, if you configure a specific HTML page differently than the domain name, then that configuration will apply. In this scenario, the user will see a Warning message but will be able to pass through to the page.

  • Headspinning
    New Member
    August 10, 2017

    Hi,

      The issue that I am observing is that when checking on the Fortiguard Webfiltering,

     

    1) example.com was categorized as Information Technology (which is allowed by fortigate webfilter profile)

    2) example.com/aa/bb categorized as Malicious Websites (which is disallowed by fortigate webfilter profile)

     

    The issue was that when the user click on example.com/aa/bb, it was allowed by the fortigate which according to the traffic log classified as Information Technology. Which leads to this question, is the Fortigate querying Fortiguard only on hostname or full url path?

     

       Hope I make it clear enough this time.

     

    Regards

    Kevin

    oheigl
    New Member
    August 11, 2017

    In the past I only thought that the hostname is queried, I was surprised that also additional paths are checked too. 

     

    In your example you mentioned: You get two different categories if you query for example on the https://fortiguard.com/webfilter website, or is it defined by you locally on the FortiGate? Another question: Is the website in question accessed via HTTPS? Maybe you have only certificate inspection enabled, and in this way only the information in the website certificate can be checked, so the additional path parameters are ignored?

    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!