Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MitchK
New Contributor

Best way to allow a site

Our Fortigate blocks sites as it should, but occasionally, we want to allow a site that would otherwise be blocked. I' ve found three ways to allow a blocked site, and I' m wondering which is the " best" way...or the reasoning you might use behind each method. Here they are: 1. In the Firewall/Address section, I created a group " Whitelisted URLs" and populated them with the URLs (from the " address" tab) to be allowed. I then construct a firewall rule to allow the " Whitelisted URLs" with no associated protection profile. 2. In the Web Filter section, I created a URL Filter containing the URLs to be permitted, in RegEx format, with the Action " Exempt" . 3. In the Firewall/Address section, I created an FQDN for each web site. I then go to the Web Filter/Fortiguard-Web Filter section and create an override for the site. Each category of blocked sites in my protection profile has overrides allowed. I believe each method works as expected. But which method should I use, and why? Thanks very much.
Mitch Fortigate-300A 4.00 (MR3 Patch5) Fortigate-200B 4.00 (MR3 Patch5) Fortigate-50B 4.00 (MR3 Patch6) FortiAnalyzer 100C (MR3 Patch1)
Mitch Fortigate-300A 4.00 (MR3 Patch5) Fortigate-200B 4.00 (MR3 Patch5) Fortigate-50B 4.00 (MR3 Patch6) FortiAnalyzer 100C (MR3 Patch1)
8 REPLIES 8
Not applicable

I have been using UTM > Web Filter > URL Filter and setting certain sites to exempt. it works just fine, but I am curious as well what the " best practice" is here and why.
rwpatterson
Valued Contributor III

Guess it depends on your individual constraints... How long do you need to bypass it? How many people involved? How long for each occurrence? Would (should) the end user be able to bypass it from the far end? etc.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

This is what we have been using as well, but we have found that ' exempt' doesn' t mean things like ' cookie filtering' won' t also be applied. Which is a pain. Even though the Help files state " stops all further checking including AV scanning." . This is probably just my misunderstanding of how it all works, but if I make a site exempt, I expect it to function as though not web filter was present at all.
MitchK
New Contributor

Assume we need to allow it permanently. For everyone. At all times. Don' t know what you mean " should the end user be able to bypass it from the far end?" . The end user can' t get to the far end, the site is blocked.
Mitch Fortigate-300A 4.00 (MR3 Patch5) Fortigate-200B 4.00 (MR3 Patch5) Fortigate-50B 4.00 (MR3 Patch6) FortiAnalyzer 100C (MR3 Patch1)
Mitch Fortigate-300A 4.00 (MR3 Patch5) Fortigate-200B 4.00 (MR3 Patch5) Fortigate-50B 4.00 (MR3 Patch6) FortiAnalyzer 100C (MR3 Patch1)
rwpatterson
Valued Contributor III

ORIGINAL: MitchK Don' t know what you mean " should the end user be able to bypass it from the far end?"
From the workstation, as the far end. Who administers the access... We use the Fortiguard web filtering, and create custom ratings. We then use these ratings in the protection profiles, and away you go. One rating is called " Windows Updates" (for obvious reasons). This one is a list of sites that anyone is allowed to access, even the restricted work stations. If we need to add another, we just place it here, and everyone can get to it.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
MitchK
New Contributor

The trouble with the ratings is you can only use a regular URL or IP address. You can' t build a RegEx filter that will grab sub-pages and sub-domains. The URL filter allows RegEx. Also, putting a firewall rule allowing access to sites as rule#1 will bypass the protection profiles altogether. This way, you get access to all the approved sites first, and eliminate the need for the Fortigate to rummage through its profiles, only to approve it anyway in the end...faster response and saved resources, no?
Mitch Fortigate-300A 4.00 (MR3 Patch5) Fortigate-200B 4.00 (MR3 Patch5) Fortigate-50B 4.00 (MR3 Patch6) FortiAnalyzer 100C (MR3 Patch1)
Mitch Fortigate-300A 4.00 (MR3 Patch5) Fortigate-200B 4.00 (MR3 Patch5) Fortigate-50B 4.00 (MR3 Patch6) FortiAnalyzer 100C (MR3 Patch1)
MitchK
New Contributor

By the way, you' re not telling me that the Fortigate blocks Windows Updates, are you?
Mitch Fortigate-300A 4.00 (MR3 Patch5) Fortigate-200B 4.00 (MR3 Patch5) Fortigate-50B 4.00 (MR3 Patch6) FortiAnalyzer 100C (MR3 Patch1)
Mitch Fortigate-300A 4.00 (MR3 Patch5) Fortigate-200B 4.00 (MR3 Patch5) Fortigate-50B 4.00 (MR3 Patch6) FortiAnalyzer 100C (MR3 Patch1)
rwpatterson
Valued Contributor III

We have a group of workstations that are not allowed any Internet access. I have had to make a way for them to get updates.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors