Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Blocked sites getting through Web Filter

Greetings, In reviewing my web filtering report of blocked and allowed sites, I have noticed that the categories that I have set to blocked still get through. For example: Category Allowed Blocked Monitored Pornography 752 8100 15927 Adult Materials 264 4382 35383 Spyware 2320 19482 223801 Is this because I have the protection profile set to Allow websites when a rating error occurs? Are there really that many rating error? What constitutes a rating error? Thanks, Steve
7 REPLIES 7
UkWizard
New Contributor

it could be that setting if all lookups are failing, like if the web category licensing isnt valid (check its valid and enabled under the category block menu) or web access is being denied (like if its in transparent mode, behind another firewall) or the protection profile isnt turned on the rule thats being hit in the policies. maybe your web traffic is hitting a different rule than you think it is.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

Hi UkWizard, I know that the web filtering license is valid. FortiGuard Status: Available [check status] License Type: Contract Expiration: Fri Mar 14 19:00:00 2008 After you posted this I checked all my rules and protection profiles again. I reset the content summary on the SYSTEM > STATUS page. That cleared all the info on the WEB FILTER > CATEGORY BLOCK > REPORT page. I did have one rule that did not have web filtering enabled on the protection profile. However, the lower rule was using a different protection profile than the one I was looking at on the WEB FILTERING > CATEGORY BLOCK > REPORTS. Basically I have two rules that allow port 80 and 443 traffic outside of the organization. One Strictly for Outbound Web traffic and a lower rule in the tree that allows port 80 and 443 traffic. I changed the lower rules protection policy to match the Outbound web traffic rule as far as categories that are monitored, blocked and allowed. Checked the WEB FILTERING > CATEGORY BLOCK > REPORTS page today and there are a number of sites that are listed as ALLOWED for categories that I specifically block. Pornography Allowed - 757 Blocked - 8598 Monitored - 15927 Spyware Allowed - 2322 Blocked - 19633 Monitored - 223801 On the Protection profile I have the following checked: Enable category block (HTTP only) Provide details for blocked HTTP 4xx and 5xx errors (HTTP only) Rate images by URL (blocked images will be replaced with blanks) (HTTP only) Allow websites when a rating error occurs (HTTP only) What am I missing? Is it the " Allow websites when a rating error occurs" that is causing the sites to get through? Thanks, Steve
Not applicable

Forgot to mention that the firewalls are in NAT mode and not behind any other firewalls. They are behind load balancers for multiple internet connections. If that matters. Steve
Andrew_Badge
New Contributor

Hi Steve, My response my be obvious or basic, so please ignore if you know this already. The forigate only scan specific ports for AV and content filtering (ie. port 80) out of the box. You can add other ports to scan eg. if you have proxy server in the DMZ (port 8080?). This is a CLI command only. This allows you to configure certain groups of users to have different protection profiles group A using profile A (Client -> DMZ) group B using profile B (Client -> DMZ) No filtering (DMZ -> Internet) maybe a waste of your time, but it wasn' t obvious to me initally (maybe i shouldn' t skim the manuals). Andrew

Hi Andrew, Thanks. I was not aware of that. However, I don' t think it will matter as we only allow port 80 and 443 out for web traffic. Steve
abelio

Checked the WEB FILTERING > CATEGORY BLOCK > REPORTS page today and there are a number of sites that are listed as ALLOWED for categories that I specifically block
Hi Steve, you can check if sites you hope or suppose be blocked for Fortiguard webfilter looking up in http://www.fortinet.com/FortiGuardCenter/webfiltering.html I found it some surprises there. regards,

regards




/ Abel

regards / Abel
Not applicable

I do actually use that site often. Problem is that I do not have a specific site that I am trying to block or allow. I guess what I am trying to do is find out why if I block all sites that are classified as SPYWARE site with the protection profile...why the system still either a) lets them through or b) blocks them but reports that they are allowed through on the report page? Am I confused as to how the web filtering is supposed to work? If I say block all sites classified as X, the system should block all sites classified as X. It should not be reporting that it blocked 80% of the sites classified as X. Steve
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors