FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
js2
Staff
Staff
Article Id 373701
Description This article describes how to allow user groups to override block categories with Web profile override.
Scope FortiGate.
Solution
  1. Configure web profile administrative override under Security profiles -> Web Profile overrides.

 

Capture.PNG

 

  1. Configure web-filter profile. In this example 'monitor all' profile is selected to block the social networking category.

 

8.PNG

 

The URL can be verified through https://www.fortiguard.com/webfilter to identify which category it falls in. 

 

  1. Enable allowing users to override blocked categories and define the user group and profile name. In the 'default' profile the social networking category is set to allow.

 

9.PNG

 

  1. Configure the web-filter profile 'monitor-all' in the firewall policy.

 

7.PNG

 

Post this configuration, and verify on generating traffic. The end user will be prompted to enter the user credentials.

Upon successful login, browse any website that belongs to the social networking category. In this example, have tried accessing Facebook.

 

1.PNG

 

Block page is received since social networking is blocked in the 'monitor all' profile. Select override and the page appears as below in this image.

 

2.PNG

 

Once the user successfully overrides, an override entry will be generated. In this example, a user group has been used instead of the user. If another user logs in and belongs to the same 'TAC group' then FortiGate allows to override transparently.

 

4.PNG

 

5.PNG

 

Related document:

Web profile override