Created on
03-10-2022
09:34 AM
Edited on
09-15-2025
12:45 AM
By
Jean-Philippe_P
This article describes the Allow, Block, Exempt, and Monitor static URL filter actions and what their functions are.
FortiGate Static URL filter with FortiGuard category filter, FortiGate Static URL filter without FortiGuard category filter.
Static URL filter with FortiGuard category filter
This can be used in two cases:
In both of these cases, it is recommended to use Web Rating Overrides and move that specific site to a new custom category, with a correct action applied in the WebFilter profile: Allow or Block, according to the needs (by default, they are disabled - neither Allow nor Block).
This is not feasible in cases where there is a need to block a very specific subdomain, in which case there is a need to use a wildcard in the Static URL filter, with the following actions:
Note:
If both the FortiGuard category-based filter and the Static URL filter are used, and it is required to allow access to a site regardless of the category, then use 'Exempt'.
Static URL filter without FortiGuard category filter:
Make sure that there is no default 'Allow all sites' option, so this Allow will only permit access to the URLs added here, and deny other access. If there is a need to block 10 URLs and allow the rest, add those URLs first, with action 'Block', then add a wildcard allow (to allow all the other URLs).
Monitor: (=Allow+'passthrough' Log) for this particular URL:
For a deeper explanation of the difference between the action 'allow' and 'exempt', may refer to this article:
Technical Tip: The difference between 'allow' and 'exempt' in the web filter URL filter
Related documents:
Technical Tip: Use static URL filtering without FortiGuard Web Filter license
Technical Note: Selecting security services for a URL with action set as “exempt” in URL filter
Technical Tip: Customize URL static filter's 'Exempt' Action
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.