Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
pctechservices
New Contributor

Allow single user to bypass web filter rptocol

Hello all, Can anyone provide guidance on how to allow a signle user, whether it be by Ip or MAC, to bypass all web filtering? I have the user set up now as an override user but would like a permanent solution. Thanks for the help, Jay
4 REPLIES 4
rwpatterson
Valued Contributor III

Welcome to the forums. Fortigates don' t speak MAC exactly. If you use DHCP on the Fortigate, you can reserve an IP address for a MAC address. If the address will not change, just create a policy with that single IP address, and place it at the top of the list of IP policies. The policies are hit from the top down and the first good one gets the traffic. Hope that helps.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
pctechservices

Bob, Thank you for the guidance. Is it possible that I expand the question? I am not actually using the Fortigate as a DHCP server, I have a DC inside the network that provides this function. I have the user set with a static IP but still cant figure out how to add this policy. I have a Fortigate 50B. Any chance to elaborate a little with exactly what section to go to inside the Fortigate? Not the most versed in networking. Thank you for all the help. Jay
Rick_H

I think Bob probably included the bit DHCP on the FortiGate simply because you mentioned MACs. Where the user station gets the IP address is less important than setting up the reservation if you decided to do the exemption via IP. However, you could also use an identity-based policy to do this. Just create a group with only this user in it and then create the ID policy to check this group while assigning it no webfilter profile.
Dave_Hall
Honored Contributor

This is a commonly requested feature and is listed in the Fortigate Cookbook...just search for " Excluding selected users from UTM filtering" .

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors