Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RolandBaumgaertner72
Contributor III

Blocking monster in URL Webfilter

Hello,

 

we have an issue with blocking hdfull.monster. We tried in Webfilter and URL filter and it would not work. Checking nslookup there are Cloudflare IPs and comparing with the test sessions I see other Cloudflare IPs.

 

Any suggestion how to block this video stream monster?

 

Thanks!

9 REPLIES 9
AEK
SuperUser
SuperUser

Hi Roland

Can you share the web filter you are using?

AEK
AEK
dingjerry_FTNT

Hi @RolandBaumgaertner72 ,

 

Not sure which one you are using, Certification Inspection or Deep Inspection.

 

And please share your configuration about URL Filter and web filter (I assume you mean Category based Filter).

Regards,

Jerry
dingjerry_FTNT

Hi @RolandBaumgaertner72 ,

 

I just did a quick test with Certification Inspection and URL Filter, it worked for me:

 

URL_Filter.png

Regards,

Jerry
jpsgps
New Contributor

I am seeing a similar issue with Cloudflare sites. 
Certificate Inspection and URL Filter are being used but the firewall does not even see the URL at all, only the IPs.

AEK

AEK
jpsgps
New Contributor

Yes, I just found some documentation about ECH from Cloudflare. I will check out this link, thanks!

jpsgps
New Contributor

We are on 7.2, doesn't look like those options are available. Guess we will have to deal with it unless there is some other way.

dingjerry_FTNT

Please see the screenshots I provided for my testing.  It's nothing to do with ECH.

Regards,

Jerry
jpsgps

I'm not sure...I am not even seeing the traffic in the Logs when searching for the URL. I can see the IP being hit but does not show the Destination URL. It shows "cloudflare-ech.com". 

At least for my particular case. 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors