Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Anonymous Proxies

I have fortiguard implemented on a college campus and have been informed by students that some have discovered web-based anonymous proxies are a great way to get around the restrictions. We need an anonymous proxy category in order to make fortiguard effective. Without it, why should I bother? A quick Google search showed me lots of options to choose from, so manually blocking these will not be an effective method for long.
7 REPLIES 7
Not applicable

There is not a specific category for this type of sites. A have noticed that a number of anonymous proxies are under the hacking category.
Not applicable

I noticed that as well after I made the post. I' m thinking that a specific category might be more helpful for fortiguard users (and perhaps a little more tightly monitored by the fortiguard team, as some very easy to find proxies were still not blocked).
Not applicable

FortiGuard Web filtering blocks sites according to the plicy if clients use a HTTP proxy on the standard port (80). If the proxy is on a port other than 80, you can add the ports into the added scanning port list. However, the anonymous proxy issues should generally be dealt with using IPS by disabling non-standard port HTTP access.
abelio

ORIGINAL: Ken Lin FortiGuard Web filtering blocks sites according to the plicy if clients use a HTTP proxy on the standard port (80). If the proxy is on a port other than 80, you can add the ports into the added scanning port list.
Hello Ken, Please, could you show how to instruct fortiguardWF to scan another port !80 ? I have not found it through the docs thanks in advance for your tip

regards




/ Abel

regards / Abel
UkWizard
New Contributor

if you find some that are not blocked, send the details to fortinet and they should evaluate it.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

To add another port for scanning use the following commands from the CLI: configure antivirus service http set port <new_port> set port <new_port2> ... end You can have as many as 20 ports configured here for scanning/filtering. Every invocation of ' set port' adds a new port to the list. To remove ports from the list, use the command ' unset port' and then add the ports you wish to scan.
surfaceshoot
New Contributor

Hi @-geometry dash, you cannot do a portforward which is forwarding ESP. I would suggest you enable NAT-T (nat traversal) on your IPSec configuration and you will only need udp ports 500 and 4500! br, Roman

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors