FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
raksshaya
Staff
Staff
Article Id 338933
Description This article describes the process of whitelisting URLs that fall under the 'Newly Observed Domain' category.
Scope FortiGate.
Solution

A URL is classified as a 'Newly Observed Domain' when its domain name is not found in the database and is detected for the first time by the FDN server.

To allow a URL that is categorized as ‘Newly Observed Domain’, use the web rating override.

 

To override the FortiGuard web rating:

  1. Go to Security Profiles, choose Web Rating Overrides, and select Create New.
  2. In the URL field, enter the website's URL for recategorization. Avoid using wildcard expressions or including HTTPS in the URL.
  3. Select 'Lookup Rating' to confirm that the URL's current categorization is set to the subcategory 'Newly Observed Domain' and falls under the 'Security Risk' category.
  4. Select the new category as 'Custom Categories' in the category drop-down menu for the Website URL and select a subcategory.


Screenshot 2024-09-04 104903.png

 

  1. Select OK
  2. After creating the override, navigate to the web filter profile and choose an action for the new category.  In the example, 'www.newwebsite1234.com' is categorized as a 'Newly Observed Domain' and is overridden by the 'custom1' category.

 

To whitelist the domain, the action for the 'custom1' category should be set to Allow or Monitor.

 

Screenshot 2024-09-04 115246.png

 

  1. Select OK
  2. Enable the web filter in the policy. 

 

Related articles
How to configure web rating override for specific web sites 

'Newly Observed Domain' Webfilter category processing logic 

Contributors