Description | This article describes how to allow user groups to override block categories with Web profile override. |
Scope | FortiGate. |
Solution |
The URL can be verified through https://www.fortiguard.com/webfilter to identify which category it falls in.
Note: Ensure that if the firewall policy is set to flow-based inspection, the web filter profile is also configured for flow-based inspection.
Post this configuration, and verify by generating traffic. The end user will be prompted to enter the user credentials. Upon successful login, browse any website that belongs to the social networking category.
The block page is received since social networking is blocked in the 'monitor all' profile. Select override, and the page appears as shown in this image.
Once the user successfully overrides, an override entry will be generated. In this example, a user group has been used instead of the user. If another user logs in and belongs to the same 'TAC group', then FortiGate allows it to override transparently.
Related document: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.