FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
yderek
Staff
Staff
Article Id 375006
Description This article describes how to block Deepseek.com using a web filter.
Scope FortiGate.
Solution

Blocking deepseek.com can be done from Web Filter, using a static URL filter:

 

webfilter.jpg

 

The expected result will be:

 

result.jpg

 

However, in certain situations, organizations have allowed ISDB to object before deepseek.com blocking policy, for example, the screenshot below, that possibly causes deepseek.com not to be blocked properly, especially containing 'Cloudflare-CDN':

 

Screenshot 2025-02-06 141809.jpg

 

Cause:

When deepseek.com has been loaded, the first hop will be Cloudflare CDN.

 

2.jpg

 

Since Cloudflare CDN has been allowed in the policy before block policies hence deepseek.com will still be able to visit.

 

Solution:

Apply application control and deep inspection in ISDB policy.

 

5.jpg

 

Blocking deepseek.com will now, work properly. However, the FortiGate block page will display application control:

 

Screenshot 2025-02-06 142707.jpg

 

Related article:

Troubleshooting Tip: Why some blocked Websites are still accessible on FortiGate