FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Anonymous
Not applicable
Article Id 280298
Description

 

This article describes the steps to restrict the Doodle Games on a search term, like Pacman, Snake and so, on by using deep inspection.

 

Scope

 

FortiGate.

 

Solution

 

Using a Web-Filter proxy-based profile with the Games category as blocked, is not enough to deny the Doodle Games, as in a search term is possible to play games like 'Pacman'.

 

doodle-002.png

 

To avoid this behavior, and to restrict this kind of game it is recommended to perform the following configuration:

 

  1. Configure a Web-Filter profile type Proxy-Based with the category 'Games' as Blocked.

 

doodle-001.png

 

  1. Configure a Static URL Filter with the wildcard domains: '*fnbx*', '*gstatic*' and '*snake*' action 'Block'.

     

    doodle-003.png

     

     

  2. Configure an App Control profile with the 'Games' category blocked and add a filter blocking the QUIC protocol.

     

    doodle-004.png

     

     

  3. On the final PC, install the deep-inspection SSL Certificate 'Fortinet_CA_SSL' on the Trusted Root Certification Authorities.

     

    doodle-005.png

     

     

  4. Finally, apply the Web-Filter, App Inspection, and deep-inspection profiles on the Firewall Policy to outgoing to the Internet.

     

    doodle-006.png

     

    After applying the configuration suggested, the Doodle Games are being restricted.

     

    doodle-007.png

Contributors