Hi there,
I've configured a DPI (with CA-cert etc) and web-filtering profile (proxy-based) successfully on FortiGate, with web-filtering configured to block access to streaming category. These profiles are applied to a proxy-based security policy.
The policy is working great, however some streaming sites are accessible for users, i.e. Crave.ca. Digging into the logs I can see the URL for the site I want to block but is accessible by the user isn't appearing in the URL field, but is appearing in the referralurl field. The FortiGate matches the URL field entry to an allowed category (i.e. 'Search Engines and Portals').
Is there a way to apply web-filtering to referral URLs as well?
Also, this behaviour is only see by FortiClient VPN users. Non-VPN users (i.e. inside) behind the FortiGate are blocked as expected for the same sites which appear as referral URL for FortiClient VPN users. Wondering why this is? Security policy is configured the same in both cases.
FortiGate version 7.4.9
FortiClient version 7.4.4
Hello Tristan,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
| User | Count |
|---|---|
| 2835 | |
| 1433 | |
| 812 | |
| 793 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.