FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
hbac
Staff
Staff
Article Id 376817
Description

This article describes an issue when FortiGate is configured to enforce Safe Search using a Web Filter profile but explicit images are still showing on the Google search engine. 

 

safe seach.PNG

 

In this scenario, SSL Security Events show that traffic to www.google.com was exempted. This means FortiGate is not inspecting HTTPS traffic. There are no related logs under Web Filter Security Events since traffic was exempted. 

 

exempt google.PNG

Scope FortiGate
Solution

This is because '*.google.com' was specified under the SSL Inspection exempt list which caused traffic to google.com to be bypassed from deep packet inspection. 

 

exempt list.PNG

 

To resolve the issue, remove 'wildcard.google.com' from the SSL Inspection exempt list. After that, Safe Search is enforced and explicit images don't appear on Google Search. 

 

safe search on.PNG

 

Related articles

Technical Tip: How SSL Exemptions affects web filt... - Fortinet Community

Technical Tip: Block images of banned categories o... - Fortinet Community

Technical Tip: Safe Search feature in FortiOS and ... - Fortinet Community