Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Allow web access only to certain hosts?

Hi All For a while, I' ve tried to do this, but given up on more than one occasion. What I want to do is allow a group of users web access to certain websites, or more specifically, to certain hosts by a program that access the internet. I thought this would be a simple matter of setting up an external address group and a policy to allow an internal group port 80 access to that group, but it doesn' t work. Can someone give me any pointers? Am I on the right lines? Thanks in advance Andy
5 REPLIES 5
wcbenyip
New Contributor III

Andy, What did you included on your external address group? If you keyin the external IP address(es) in that group and set a proper fw policy, I do think that it should work~
Protect yourself~ http://www.secunia.com MBCS CEH FCNSA
Protect yourself~ http://www.secunia.com MBCS CEH FCNSA
Not applicable

[Deleted by Admins]
Not applicable

Thanks, I' ve had some limited success now with using address group > address group policies, which is what I was doing before. I think that address resolution from a FQDN in a browser is still a problem, but I should be able to get around it. Thanks for your suggestions. Andy
rwpatterson
Valued Contributor III

A Fortinet tech told me that with 3.0 bld 3.18, FQDNs are a problem, and to use IP addresses. I just ' graduated' from Symantec Gateway Security world, and over there, I just had one big ol' group of about 60 addresses that the entire organization could get to. When I tried that in Forti-world, the policies failed open, and everyone could surf the ' net, regardless of policy settings. I figured out that the way to go is via URL filtering. I moved those same addresses into a group (Web Filter -> URL Filter), and made the very last regex entry .* (everything else), and denied it. If they didn' t hit on the prior 60 entries, they ain' t getting out! regex for dummies: I you want you users to get to www.foo.com, or just foo.com, the regular expression (A.K.A. regex) would be: w{0,3}\.foo.* w{0,3} = the letter ' w' repeated 0, or three times \. = the dot is a special character, and has to be escaped to be read as expected foo = the domain (be it google, ebay, whatever) .* = anything 0 or more characters, repeated 0 of more times If the URL doesn' t begin with triple w, replace w{0,3} with the host name. I omitted the top level domains for simplicity. If a URL starts with foo, and ends in .porn.com, they could still get to it with my definitions, but that' s what Fortigaurd web filtering is for! Done!!! Angry users = happy firewall admin. I' m doing something right. :)

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

[Deleted by Admins]
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors