Created on
12-05-2014
08:03 AM
Edited on
05-14-2025
02:13 AM
By
Jean-Philippe_P
Description
This article describes how unsafe content is still being displayed even though Safe Search is enabled in the Web Filter profile applied to a firewall policy.
Scope
FortiGate.
Solution
Reason:
Since Google Search uses secure traffic (HTTPS), encrypted connections must also be scanned for this feature to be effective.
Note:
On newer versions of the FortiOS, the view of the SSL/SSH profile and the Web Filter profile has changed.
The suggested SSL profile to be used on newer versions would be the custom-deep-inspection one, as it can be edited and customized.
By disabling the option 'Inspect all ports' on Protocol Port Mapping, it is possible to enable or disable each of the options mentioned below:
On the next step, the Safe Search option is enabled on the Web Filter profile.
As the default profile cannot be edited, this profile can be cloned or a new custom profile can be created.
This feature is only supported if the Web Filter is set to Proxy mode, so it will look like it follows, after Proxy mode is enabled:
On version v7.4.7 and v7.6.3, the 'Restrict YouTube Access' option is also removed:
The option 'Scan Encrypted Connections' is also removed on the mentioned versions.
Related articles:
Technical Tip: Safe Search feature in FortiOS and how to enable it
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.