Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sourabha
New Contributor

Blocking Websites for the users connected to a wireless router

Hello,

My fortiGates port 2 interface is connected to a wireless router. The router IP is say 192.168.10.5 and my interface port 2 IP is 192.168.10.1. The routers DHCP is on and DHCP pool is say 192.168.1.2.to 192.168.1.50. The user connects and get IP from that range. How can i block Adult/Mature content for those user?

I tried creating a separate policy with from as port2 and to as WAN1 and appliying web filter to that policy, it did not work. Also created a network range 192.168.1.2-192.168.1.50 and added it to source but still did not work. I am not able to see any logs for these ip addresses under fortiview.

 

Please help 

2 REPLIES 2
Dave_Hall
Honored Contributor

Check the fgt's routing table to see if there is a 192.168.1.x route to port 2 (interface).  If the 3rd party router is performing NAT then all you may see is traffic from 192.168.10.5 only.  Ideally, you would want to place the 3rd party router into AP mode if all possible. 

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
nbctcp
New Contributor III

What @Dave said is correct

1. set AP in Bridge mode, so users will get ip in this subnet 192.168.10.0

http://goo.gl/lhQjmUhttp://nbctcp.wordpress.com
Labels
Top Kudoed Authors