Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
GTNman
New Contributor

Blocking Internet by Usergroup.

Here the story... two groups of users, one access the internet, the other not so much. Currently, I have the groups authenticating via FSAE and the connection between FSAE and my DC' s are working just perfect. Firstly, the Authentication redirect page does not work properly. Nothing redirects. Secondly, is there a better way to block all internet access than how I currently have it set up? For the group that will not be allowed to access the internet the corresponding firewall policy will only allow users to access DNS thus blocking any other protocol requests. The problem I have with this method is it doesn' t notify the users the sites are blocked, it simply wont load. I have tried setting up wildcards and regular expressions to block all websites in Web filter > Content Block but I do not believe I did it properly as all sites structured as www.something.com are blocked but mail.yahoo.com will get through. Any additional insight on this would be greatly appreciated!
7 REPLIES 7
rwpatterson
Valued Contributor III

Set up Fortiguard web filtering to block all sites. Create a small local group of the sites you want (if any), and then add this to your protection profile (I allow Windows Updates to all users, regardless if denied Internet or not). Add this protection profile to your policy, and then select accept (NOT DENY!!). The Fortiguard will respond that the site has been blocked.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
GTNman
New Contributor

Ah, if only I had a subscription to Fortiguard. I have to do this sans fortiguard.
doshbass
New Contributor III

fortigate without fortiguard is like bread with no jam - functional but not tasty.
Still learning to type " the"
Still learning to type " the"
GTNman
New Contributor

well no money in the budget for it, so there for any help with structing a regular expression to filter it all out would be much appreciated.
rwpatterson
Valued Contributor III

I' m not sure, but I think the only way to present something to the end user is with Fortiguard services of some extent.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
abelio

Hi Jared, No problem; try with " URL Blocking" feature. If you want block every site on the Net, use the regexp: ^.*$ Then you can configure 2 usergroups and authenticate them: full web-access and no web-access Another possibility is use that with an ' exemptions' list of web sites to permit some websites and block anything else with the regexp. Relevant thing for your question: the order; I mean: http://www.yahoo.com/r/2h allow http://www.yahoo.com block permit you can see ' r/2h' but not the whole yahoo site Inverse order doesn' t hope it helps,

regards




/ Abel

regards / Abel
GTNman
New Contributor

Abel- Thank you very much this is exactly what I needed... I do not know why I couldnt figure out such a simple reg ex, needless to say.... thanks.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors