FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
raureada
Staff
Staff
Article Id 314172
Description

This article describes how to allow the website with an Unrated Category.

Scope FortiGate.
Solution
  • When accessing the site, the below error is received:

 

unrated1.JPG

 

  • Upon checking on the DNS Query logs, the Action was set to redirect:

 

unrated2.JPG

 

  • Check the DNS servers and it was UP:

 

unrated3.JPG

 

  • Upon checking on the lookup:

 

unrated4.JPG

 

  • It was resolved on this address 208.91.112.55, which is the FortiGuard 'Redirect Portal' IP address used by DNS filtering. 
  • This happens when the website belongs to a Category in the DNS filter's 'FortiGuard Category Based Filter' and the category is set to action as 'Redirect to Block Portal'.

 

dnsredirect.PNG

 

  • To fix this, a DNS 'Static Domain Filter' needs to be enabled, and an entry needs to be added to the override category based filter to allow the website:

 

unrated5.JPG

 

  • Now the website is accessible:

 

unrated6.JPG

 

Static URL filtering can also be utilized to allow an UNRATED category website. For that, open the web filtering profile that is being used in the firewall policy and create a new static URL filter with the action set as EXEMPT.

 

Note:

Using the EXEMPT action will bypass all filter checks without any further scanning.

 

Refer to this article on how to create a static URL filter:

Technical Tip: Using a static URL filter feature to allow/block web sites


Related articles:
Technical Tip: Using a static URL filter feature to allow/block web sites 

Technical Tip: Difference between action 'Allow' and 'Exempt' in static URL filter 

Technical Tip: Using a static URL filter feature to allow/block web sites 


Related Video: