Hi all,
I've been using the FortiClient on Windows/Mac PCs for a while now and feel that the web filtering capabilities work the way I envisioned them, ie: the clients will have certain web filtering profiles that will be active on their computers no matter which browser they use.
Recently I wanted to get a feel for the Mobile clients to see how they handled the webfiltering, and to be honest from what I've seen so far I can't see how this can be useful in a business/enterprise scenario.
I was hoping you guys could illuminate if my below conclusions are correct or if there's something crazy that I'm missing here.
I'm trying to test a generic scenario like a business or school wants to control all webtraffic that their users/students goto with their remote device. They would like certain websites blocked, and all websites monitored so they can track usage when the devices are out of the office/school. The users should have not be able to disable the webfiltering.
From my testing so far I can see the following:
1. The only way webfiltering will work is if the user connects to a VPN tunnel back to the FortiGate
2. The VPN connection itself is totally optional and controlled by the user.
Result: The users never have to connect to the VPN and thus are not forced to be restricted by the webfiltering profile. They can go home and surf whatever they want, without enabling the VPN. No options are available to force the VPN connection when outside the network.
1. Webfiltering only works if the user browses through FortiClients own browser. It will not work through Safari, Firefox etc.
Result: Clients have to voluntarily use the built-in browser to search to have their web browsing controlled/monitored. There may be a possible way of disabling Safari & other browsers through the config but this could potentially break other applications.
Does the above sound about right to you guys? I was hoping the FortiClient Mobile webfiltering capabilities would be like the desktop version where all outbound connections were transparently proxied by the client and FortiGuard queries were send directly from the device without needing to dial back to a FortiGate.
You are right.
Thanks for confirming Chris.
FortiClient says Android OS v4.4.0-4.4.2 does not support VPN Apps. Please upgrade to Android v4.4.3 or later (Samsung Galaxy S5 that version is not currently available).
//eSalo
| User | Count |
|---|---|
| 2980 | |
| 1469 | |
| 936 | |
| 826 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.