You can activate SSL Inspection and only check the website CN (hence preventing all the crazy certificate warnings that you're getting), here's how: http://docs.fortinet.com/uploaded/files/1705/fortigate-https-webfiltering-without-ssl-deep-scan-50.p...
Also, if you DO want Deep Inspection (Full SSL Inspection) you can use the procedure outlined here: http://cookbook.fortinet.com/preventing-certificate-warnings/
If you have a big network and Active Directory you can also distribute the CA certificate using GPOs.
SSL inspection won't work in this case because google translation uses google's wildcard security certificate.
There is an application filter for "google.translate" that you could try adding to your exist app sensor that covering web traffic. Set the filter to block.
Alternately, you could try the old-school method by blocking the site via FQDN. NSlookup shows translate.google.com resolves to www3.l.google.com (with about 12 IP addresses), it may work. Create a FQDN address label for the site, create the firewall policy then move it up the firewall chain so it can get triggered.
Edit: Never tried to block translate.google.com by FQDN before, so I am hoping this method doesn't block legitimate google traffic.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
I'd seriously consider upgrading to 5.2.2 or at least 5.0.9 if for no other reason than using the much improved SSL inspection capabilities for webfiltering.
I remember from my pre-Fortinet days 4-5 years ago.Google Translate Bypass used to work for other URL Filters also like WebSense.
I just had a look and I am able to bypass Filtering using Google Translate.
Ahead of the Threat. FCNSA v5 / FCNSP v5
Fortigate 1000C / 1000D / 1500D
Dipen wrote:I remember from my pre-Fortinet days 4-5 years ago.Google Translate Bypass used to work for other URL Filters also like WebSense.
I just had a look and I am able to bypass Filtering using Google Translate.
This was fixed on 5.2.2
Regards, Paulo Raponi
User | Count |
---|---|
2087 | |
1181 | |
770 | |
451 | |
344 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.