Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
LanceMc
New Contributor

DNS web filtering instead of SSL inspection?

Hi, I want to set up some basic web category filtering for our school. A common problem is that we can block " http://facebook.com" but we can' t block " https://facebook.com" . Is there an easy way to do this without setting up SSL Inspection? I have seen articles about DNS Inspection mode for the web filtering but no doc on how to set it up. Do the clients need to use the Fortigate as their DNS server? Currently we use internal MS dns with forwarding to external (ISP) dns. How would this need to change to use DNS mode? TIA
11 REPLIES 11
emnoc
Esteemed Contributor III

Just to be clear... before v5 non deep SSL inspection used only certificate CN thus Google sites could not be differentiated.

 

BTW the  certificate "CN"  is  ignore in ALL major web-browsers when a AltName is present.

 

Back to te OP, you could also use a Explicit proxy and block the website without setting up SSLinspection.

 

Ken

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
norascott
New Contributor

I was creative my first website by download WordPress free themes from sktthemes.net. the website run smoothly but applying SSL to the domain it occurs DNS server error. What is the solution of this error? please help me.

Labels
Top Kudoed Authors