Description | This article explains how to configure the static URL filter in a Web Filter profile to permit access only to specified URLs while blocking all others. |
Scope | FortiGate. |
Solution |
Certain scenarios require restricting access to whitelisted URLs exclusively through the Web Filter UTM feature, avoiding the use of the destination field in the firewall policy. This can be achieved by using the 'Static URL Filter' feature within the Web Filter options. The 'Static URL Filter' does not include a catch-all entry by default, so one must be added manually to block access to all other destinations.
The following diagram shows a sample configuration scenario:
URL: *
Note: The order of entries is important, as they are evaluated from top to bottom. Firewall Policy configuration:
config firewall policy
Web Filter configuration: config webfilter profile
URL Filter configuration: config webfilter urlfilter
GUI configuration example:
Related documents: Technical Tip: Using a static URL filter feature to allow/block web sites |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.