This article describes the working flow of offline web-filtering functionality on a FortiGate (for DoT Compliance).
FortiGate.
Diagram:
Working Flow:
For example:
config system ips-urlfilter-dns
edit 4.2.2.2
next
edit 8.8.8.8
next
end
config webfilter ips-urlfilter-setting
set device “port x" <----- Upstream port.
set distance 10
set gateway <x.x.x.x> <----- Next hop IP of upstream port.
end
'Set Device' as egress interface or upstream link, with the next-hop IP as 'Gateway' and with the same distance as configured for the default static route.
Note:
This enables the device to auto-configure static routes with the auto-resolved website IP addresses pointing to the upstream link.
These static routes are redistributed to the Gateway router via the Downstream iBGP session.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.