Description | This article describes why category-based FortiGuard web filters can be bypassed. Instead of following the action set by the web filter, it can follow the application control profile also, a workaround to mitigate the scenario. |
Scope | FortiOS. |
Solution |
The web filter and application control can be set into the same firewall policy for general purpose and regular use. Harmful sites like hacking, weapons, drugs, etc. can be blocked with a FortiGuard category-based web filter.
In some scenarios, the web filter can be bypassed if there is an application control and it detects the content signature while the web content keeps loading and the application control profile detects the signature is not a high risk. For this scenario, the following logs can be noticed in the traffic log.
It can be noticed that the application control profile found the category is network service and allowed it after matching the app control signature, which is expected. To avoid this scenario, the following workaround can be followed.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.