I have a few whitelists of URLs that have been developed over time to match user needs.
I want to implement them on a new Fortigate 80_F 6.4.10.
My preferential approach is to have things as separate and distinct as possible. And, my notion is to have the firewall policies ordered so that the process will be fast and efficient.
I have firewall policies for:
Whitelist for all - so there are no names and Source is just "all". Uses a Static URL filter only.
Whitelist for buyers - trying to use a short list of names as Source. Not working yet but OK for this question.
Whitelist for others - same
DNS with DNS profile
HTTP-HTTPS with WEB, AV and APP profiles
Applications - with APP profile.
Social - with web profile
Catch-all - with web profiles
The idea is that these policies will either be acted on or skipped because they don't apply..
I wouldn't want one to overcome those remaining by letting unwanted traffic through.
Is that an issue and how to understand and deal with that?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
@gfleming Thank you!
and ... thank everyone in this thread!
@gfleming : OK well that makes it clear enough. So, what is the difference between one of these web rating overrides and a Static URL filter? I was given the impression (separately) that a static URL filter combined with a category filter would "let anyone through" which I didn't fully understand. Thus this question was posted.
There's no real difference. Both can accomplish the same thing. From my perspective given what you are trying to accomplish I would think using overrides would be simpler. However, yes you can also use URL filter to exempt these sites to whitelist them as well. The choice is yours... I suggest you review the docs and figure out which one makes most sense for you based on what you assume to be your configuraiton and workload in implementing it:
https://docs.fortinet.com/document/fortigate/7.2.2/administration-guide/615462/url-filter
https://docs.fortinet.com/document/fortigate/7.2.2/administration-guide/122974/web-rating-override
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1645 | |
1070 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.