Skip to main content
Baboda
New Member
April 7, 2017
Question

wildcard FQDN policy

  • April 7, 2017
  • 5 replies
  • 12640 views

Hello,

with FortiOS 5.2.9 is see wildcard FQDN address is not supported. What I need to do is create a policy which deny all except (for example) *.google.com. I could create a webfilter profile with a static wildcard url filter and then assign it to the ipv4 policy maybe ? but how can I deny all the other traffic ?

 

 

Thanks

    5 replies

    hklb
    Visitor III
    April 7, 2017

    Hi

     

    With URL filter :

    - *.google.com  :exempt 

    - * : deny 

     

    Lucas

    Baboda
    BabodaAuthor
    New Member
    April 8, 2017

    Thanks Lucas,

    that is also what I was thinking to do with a url filter deny * in web filter profile (other then exempted ones). Another question is if exempting google or lets suppose any other site, even malicious ones, does it means that those sites are totally exempted even though for example included in a not allowed category in the same web filter profile ?

    hmtay_FTNT
    Staff
    Staff
    April 8, 2017

    Hello Baboda,

     

    >>Another question is if exempting google or lets suppose any other site, even malicious ones, does it means that those sites are totally exempted even though for example included in a not allowed category in the same web filter profile ?

     

    Yes, it will be exempted from the FortiGuard categories too.

     

    HoMing

    Baboda
    BabodaAuthor
    New Member
    April 10, 2017

    Thanks a lot, just the last question is what in url filter the "monitor" action difference to "exempt" or "allow" ones.

    Baboda
    BabodaAuthor
    New Member
    April 11, 2017

    Perfect! thanks a lot :)

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!