Hello,
We are a school district that just switched from Cisco ASA devices to FortiGate 201E firewalls for our schools. Our firewall is in flow-based inspection mode and is on version 5.6.3. We block Facebook, but want to allow just the principal to access it to update the school's Facebook page. Is there a way to whitelist his IP/MAC address or have a way for him to log in to get to Facebook?
Thank you.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Create a new policy and put the principal's device's IP in source address, then allow whatever you want to allow as services then place it above the existing policies. Don't forget to enable nat.
Thank you. I'll have a look at that.
Seems the feature webfilter web override supports that function. It is working for proxy-based utm. For flow-based utm, the feature has been finished porting but haven't been committed to trunk. It should be available in FOS v6.x release (approximately, depends on developer porting the feature).
Thank you Darwin. I'll have a look at the possibility of an OS upgrade.
Might be better/safer/simpler to just have a duplicate security policy for your principals user account / device with a different web filter, rather than upgrade the OS.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1711 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.