| Description | This article describes how to use the Exempt option in the Webfilter URL filter to control scanning. Once the Exempt is enabled in the URL filter for any URL, the URL will bypass all other scanning such as antivirus or DLP, etc. There is an option only in CLI to control which scan can be exempted and which should still need to be scanned. |
| Scope | FortiGate. |
| Solution |
The 'Exempt' action for a defined URL in the URL filter will permit the traffic to pass through the firewall without any further scanning. There will be no match against FortiGuard web filters (FortiGuard categories), Web Content Filter, or so on, however there might be a need to further scan the traffic and take action. There is an option in CLI to control which scan can be exempted and which traffic still needs to be scanned further. This could be achieved via the below options under the exempt hierarchy for URL:
av AntiVirus scanning.
This feature is helpful, where the requirement is to further scan the traffic post using the Exempt option, in those situations, it is possible to use the above options in a static URL filter and the configuration could be done via cli only.
config webfilter urlfilter |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.