Created on
12-19-2024
04:12 AM
Edited on
06-12-2025
10:34 PM
By
Jean-Philippe_P
Description | This article describes how to work around the issue when some websites of a specific category in Web Filter are not getting blocked in Google Chrome, despite the category being blocked in Web Filter. |
Scope | FortiGate v7.2. |
Solution |
eventtime=1729788324734273772 tz="-0700" logid="0317013312" type="utm" subtype="webfilter" eventtype="ftgd_allow" level="notice" vd="root" policyid=14 poluuid="062105c8-919c-51ef-c75a-250268491a04" policytype="policy" sessionid=1327 srcip=10.1.10.1 srcport=56430 srccountry="Reserved" srcintf="port2" srcintfrole="undefined" srcuuid="fb73f05a-919a-51ef-6819-878047fdfc5f" dstip=172.67.223.251 dstport=443 dstcountry="United States" dstintf="port1" dstintfrole="undefined" dstuuid="fb73f05a-919a-51ef-6819-878047fdfc5f" proto=6 service="HTTPS" hostname="cloudflare-ech.com" profile="webfilter_profile" action="passthrough" reqtype="direct" url="https://cloudflare-ech.com/" sentbyte=1952 rcvdbyte=0 direction="outgoing" msg="URL belongs to an allowed category in policy" ratemethod="domain" cat=52 catdesc="Information Technology"
CloudFlare DNS may use the same IP addresses for different domains. This is completely normal and part of how reverse proxy and CDN (Content Delivery Network) services work. CloudFlare acts as an intermediary between visitors and the websites’ actual servers (origin). When a domain is using CloudFlare, its public IP address will be one of CloudFlare’s IP addresses, not the actual IP of the website’s server. This is why blocking only the IP can block other websites contained in CloudFlare's DNS.
Workaround:
CLI:
set url "*cloudflare*"
GUI:
Related article: Technical Tip: How to block TLS 1.3 Encrypted Client Hello (ECH) in FortiGate firewalls |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.