FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ibituya
Staff
Staff
Article Id 364911
Description

This article describes creating a video filter profile to restrict YouTube videos based on FortiGuard categories without using an API key.

Scope

FortiGate 7.0.0 and later.

Solution

The video filter profile is an additional security feature that can restrict YouTube videos based on FortiGuard categories. The following points should be taken into consideration when enabling a video filter:

 

  • The video filtering service requires a valid FortiGuard web filter license.
  • The video filter profile is currently supported by proxy-based policies.
  • SSL deep inspection is required when enabling a video filter profile.
  • It is recommended to block the QUIC protocol in the application control profile while applying the video filter profile to allow the FortiGate to successfully inspect the traffic using TCP/443.

 

To configure the video filter based on FortiGuard categories:

 

  1. Create the video filter profile under Security Profiles -> Video FilterIf the Video Filter is not visible, enable it under System -> Feature Visibility.
  2. Enable FortiGuard Category-Based Filter and select the needed action for each category (allow/block/monitor). For example, in this case, the Sports category is set to Block.

 

ibituya_0-1734335117601.png

 

  1. Create the firewall policy and enable the video filter.

       Note: Proxy-based inspection and SSL deep inspection are required with a video filter.

 

ibituya_1-1734335117608.png

 

  1. The block page will be displayed if a sports-related video has been accessed.

 

ibituya_2-1734335117612.png

 

Related document:

FortiGate 7.2.10 Administration Guide