Description |
This article describes what to check if web filtering is not working properly. |
Scope | FortiGate. |
Solution |
The web filtering feature is a tool to control and monitor internet usage, ensuring that users adhere to organizational policies by preventing access to unwanted or harmful content. However, if web filtering is not functioning as expected, it is likely due misconfigurations between the firewall policy and the web filtering profile modes. Follow the steps in this article to troubleshoot and resolve this issue.
FortiOS supports two primary web filtering modes:
If web filtering is not working as intended, it is crucial to verify that both the firewall policy and web filtering profile are configured to operate in the same mode. A mismatch between these modes can lead to ineffective filtering and security gaps.
To configure in the CLI:
config firewall policy edit "1" set name "LAN_WAN" set inspection-mode flow set webfilter-profile "default" end
After, check the web filtering profile it is being used for under the same Firewall policy: navigate to Security Profiles -> Web Filter -> Edit the profile to use in the firewall policy.
To configure on the CLI:
config webfilter profile edit "default" set feature-set flow end
Note: As of v7.2.4, the default inspection mode for Firewall policy and Web filter is set to flow.
Related document: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.