Hello All,
In Fotigate firewall, can someone guide how can we allow a specific full/exact URL as below only,
https://code.ionicframework.com/ionicons/2.0.1/css/ionicons.min.css
Thanks,
After creating the Web filter as desired, i shall create a policy for it. Can you please guide on the policy, as well?
Source: Devices to be allowed.
Destination: All?
Service: HTTPS
Action: ACCEPT or DENY ?
Webfilter: Select the one i created.
SSL inspection: certificate-inspection.
Thanks,
Hello
Destination in this case can be all since nevertheless you will block everything through UTM and will filter by source to the specific subnet you want this rule to apply.
Service I would suggest "ALL"
Action would of course be accept in order to allow the traffic to traverse the device.
Inspection: certificate inspection if you want to only check the SNI on the certificate of the website
deep inspection if you want the traffic to be decrypted and the payload to be inspected as well. This will generate an error into the browser if the cert is not added into the trusted CA of the browser itself.
Hello @ezhupa
Thanks for your response and clarifications.
To update, currently i have configured as follows,
Source: Devices to be allowed.
Destination: FQDN (code.ionicframework.com)
Service: HTTPS
Action: ACCEPT
Webfilter: Select the one i created with wildcard, exempt action.
SSL inspection: certificate-inspection.
I have also enabled the default AV and IPS profiles.
Will change accordingly if any issue/blocks are faced.
Thanks again,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1751 | |
1114 | |
766 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.