hello
I integrated freeradius server with fortigate , but when I reading about fortinet radius server I found this attribute
Fortinet-Webfilter-Category-Block which mean I can block websites from freeradius using that attribute in reply section .
but when I applied this attribute it give me error and deny user from access internet
the definition of this attribute tell us that we must using octets value
Fortinet-Webfilter-Category-Block 17 octets
but if I want to block facebook for example what should I using as value of that attribute ? please help me
I didn't know it's supported. Can you share where you read it? Only attributes I know were in below:
http://kb.fortinet.com/kb....do?externalID=FD30830
But if supported, likely it's expecting one of numbers (or multiple) from below:
http://kb.fortinet.com/kb/viewContent.do?externalId=FD30715
Facebook is not a category. It's a part of Social Networking.
https://fortiguard.com/webfilter?q=facebook.com&version=8
So if the category attribute worked, I would define it and include in one of local categories, which you can see the ID in CLI, then specify it with the attribute. Again, I didn't know it was supported so I never tested it.
thank you for reply
in this web page there are new attributes which shared from fortinet
http://kb.fortinet.com/kb/viewContent.do?externalId=FD36919&sliceId=1
Thanks!
but as you see the attributes value is octets so how can I configure it ?did you mean I will set value like this
Fortinet‐Webfilter‐Category‐Block:= g02 g03 g04 g05 g06 g07 g08 g21 g22 c01 c02 c03 c04 c0
if u working on fortigate and freeradius we can share our knowledge between us
this is my whatsapp number :00905373545631 and I wish to contact me
I think that "Octets" mean it's NOT either "ip address" or "string". In other words integer.
Have you tried like below?
Fortinet‐Webfilter‐Category‐Block:=17
I don't tried it yet because now I at holiday but I will try it when I can , thank you very much for your help
but I have another problem and I don't know if you have any solution for it, my boss asked me to control user's bandwidth but I don't find any attribute belong to fortinet to limit bandwidth, do you know how can I do that ?
Probably you're lookin for "Per-IP shaper". Go to online help below and choose your version, like 5.4, 5.6, 6.0. Then search "traffic shaping methods". It would tell you how to set up a shaper and a shaping-policy. You might need to set separate IP ranges for different levels of allowed bandwidths. I don't think you can directly specify a shaper from RADIUS. You need to use either IP or group.
http://help.fortinet.com/fos50hlp/56/Content/FortiOS/fortiOS-HTML5-v2/Home.htm
I added this attribute to user's reply attribute if freeradius
Fortinet-Webfilter-Category-Block := 37 to block social media but it appears in hex like this
Fortinet-Webfilter-Category-Block := 0x3337
and when I trying to access facebook I can access it without problem , what do you think I must add as value for attribute to make it working
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.