I have a requirement where i need to allow access from a specific internal source to a no of internet URLs.. the destination here not be any IP addresses..they will be a couple of URLs.. how can i achieve this in fortigate ?
any help is appreciated
thanks
Hi,
You can have a look at
thank you for the reply .. i went through the links and it seems like i can get this to work via webprofile..if i understand this correctly i should create a new webprofile and add the URLs i want to access.. add them to the policy but the destination in that case should be kept as "any" ?
also..i was wondering if FQDN addresses in destination field will work for my use case
I have the same thought around adding the FQDN addresses as destinations instead of any. In the web filter policies, all categories are blocked and only those specific URLs defined in the static URL filter are set to allowed, or exempt or monitor. Any thoughts?
i would leave any as destination since a URL can be resolved by the DNS of the client in a IP and the FGT would/could resolve it in a another.
but you can give it a try.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-a-wildcard-FQDN/ta-p/196118
Thanks for the recommendations.
As for the second part, "In the web filter policies, all categories are blocked and only those specific URLs defined in the static URL filter are set to allowed, or exempt or monitor. " Is this the best way to achieve? Thanks!
i would exempt them and block all other categories if you only need access to those urls and nothing else.
also in the firewall rule would only allow http and https
| User | Count |
|---|---|
| 2919 | |
| 1452 | |
| 855 | |
| 826 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.