Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tristanv
New Contributor

DPI & WF for "referralurl"

Hi there,

 

I've configured a DPI (with CA-cert etc) and web-filtering profile (proxy-based) successfully on FortiGate, with web-filtering configured to block access to streaming category. These profiles are applied to a proxy-based security policy. 

 

The policy is working great, however some streaming sites are accessible for users, i.e. Crave.ca. Digging into the logs I can see the URL for the site I want to block but is accessible by the user isn't appearing in the URL field, but is appearing in the referralurl field. The FortiGate matches the URL field entry to an allowed category (i.e. 'Search Engines and Portals').

 

Is there a way to apply web-filtering to referral URLs as well?

 

Also, this behaviour is only see by FortiClient VPN users. Non-VPN users (i.e. inside) behind the FortiGate are blocked as expected for the same sites which appear as referral URL for FortiClient VPN users. Wondering why this is? Security policy is configured the same in both cases.

 

FortiGate version 7.4.9

FortiClient version 7.4.4

2 REPLIES 2
Anthony_E
Community Manager
Community Manager

Hello Tristan,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
ebilcari
Staff
Staff

Basically all URLs accessed by the end host, both directly and indirectly should be evaluated by the security policies. In this case, the issue may be that this streaming sites are using legitimate CDN URLs to deliver their content. Are the VPN users using full tunnel mode including the DNS traffic?

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors