Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fred339
Contributor

Converting to a Fortigate firewall with user-assigned whitelists

I have a few whitelists of URLs that have been developed over time to match user needs.

I want to implement them on a new Fortigate 80_F 6.4.10.

My preferential approach is to have things as separate and distinct as possible.  And, my notion is to have the firewall policies ordered so that the process will be fast and efficient.

I have firewall policies for:

Whitelist for all - so there are no names and Source is just "all".  Uses a Static URL filter only.

Whitelist for buyers - trying to use a short list of names as Source.  Not working yet but OK for this question.

Whitelist for others - same

DNS with DNS profile

HTTP-HTTPS with WEB, AV and APP profiles

Applications - with APP profile.

Social - with web profile

Catch-all - with web profiles

 

The idea is that these policies will either be acted on or skipped because they don't apply..

I wouldn't want one to overcome those remaining by letting unwanted traffic through.

Is that an issue and how to understand and deal with that?

 

 

Fred Marshall
Fred Marshall
12 REPLIES 12
fred3
New Contributor II

@gfleming Thank you!

and ... thank everyone in this thread!

fred339
Contributor

@gfleming :  OK well that makes it clear enough.  So, what is the difference between one of these web rating overrides and a Static URL filter?  I was given the impression (separately) that a static URL filter combined with a category filter would "let anyone through" which I didn't fully understand.  Thus this question was posted.

Fred Marshall
Fred Marshall
gfleming

There's no real difference. Both can accomplish the same thing. From my perspective given what you are trying to accomplish I would think using overrides would be simpler. However, yes you can also use URL filter to exempt these sites to whitelist them as well. The choice is yours... I suggest you review the docs and figure out which one makes most sense for you based on what you assume to be your configuraiton and workload in implementing it:

https://docs.fortinet.com/document/fortigate/7.2.2/administration-guide/615462/url-filter

 

https://docs.fortinet.com/document/fortigate/7.2.2/administration-guide/122974/web-rating-override

Cheers,
Graham
Labels
Top Kudoed Authors