FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
dbhavsar
Staff
Staff
Article Id 348963
Description This article describes how to access the root domain site while blocking its sub domains.
Scope FortiGate.
Solution

For example, the configuration below shows how to allow www.oracle.com while blocking www.oracle.com/java/technologies/downloads/

 

The website 'www.oracle.com' belongs to the General Interest. Information Technology category which is allowed in the below screenshot.


Web-filter configured as follows:


web-filter.pngThe firewall policy is configured as follows:


policy.png

As per the screenshot, www.oracle.com is accessible and www.oracle.com/java/technologies/downloads/ is getting the blocked page.


website.png
Note:

Deep Packet Inspection must be used in the policy or else the web-filter will not be able to block the exact destination URL.