Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
neonbit
Valued Contributor

FortiClient for Mobiles with Web Filtering - How does it really work?

Hi all,

 

I've been using the FortiClient on Windows/Mac PCs for a while now and feel that the web filtering capabilities work the way I envisioned them, ie: the clients will have certain web filtering profiles that will be active on their computers no matter which browser they use.

 

Recently I wanted to get a feel for the Mobile clients to see how they handled the webfiltering, and to be honest from what I've seen so far I can't see how this can be useful in a business/enterprise scenario.

 

I was hoping you guys could illuminate if my below conclusions are correct or if there's something crazy that I'm missing here.

 

I'm trying to test a generic scenario like a business or school wants to control all webtraffic that their users/students goto with their remote device. They would like certain websites blocked, and all websites monitored so they can track usage when the devices are out of the office/school. The users should have not be able to disable the webfiltering.

 

From my testing so far I can see the following:

FortiClient Android:

1. The only way webfiltering will work is if the user connects to a VPN tunnel back to the FortiGate

2. The VPN connection itself is totally optional and controlled by the user.

Result: The users never have to connect to the VPN and thus are not forced to be restricted by the webfiltering profile. They can go home and surf whatever they want, without enabling the VPN. No options are available to force the VPN connection when outside the network.

 

FortiClient iOS:

1. Webfiltering only works if the user browses through FortiClients own browser. It will not work through Safari, Firefox etc.

Result: Clients have to voluntarily use the built-in browser to search to have their web browsing controlled/monitored. There may be a possible way of disabling Safari & other browsers through the config but this could potentially break other applications.

 

Does the above sound about right to you guys? I was hoping the FortiClient Mobile webfiltering capabilities would be like the desktop version where all outbound connections were transparently proxied by the client and FortiGuard queries were send directly from the device without needing to dial back to a FortiGate.

3 REPLIES 3
Chris_Lin_FTNT

You are right.

neonbit
Valued Contributor

Thanks for confirming Chris.

esa_salo
New Contributor

FortiClient says Android OS v4.4.0-4.4.2 does not support VPN Apps.  Please upgrade to Android v4.4.3 or later (Samsung Galaxy S5 that version is not currently available).

 

//eSalo

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors