Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Laniver
New Contributor II

Fortigate firewall static URL not exempting URLs from web filter

The firewall is running version 7.2.10.

I have a set of rules which has web filters, IPS and DNS filters enabled.

 

The web filter is set to warning for unrated websites. I have set several static URL filters to exempt certain URLs from web filtering, but it is apparently still being blocked by web filtering.

 

How do I ensure the static URL filters work for exempting URLs from web filtering?

12 REPLIES 12
dingjerry_FTNT

Hi @Laniver ,

 

I have no access to this https://c1-ny-cvx.anw.cz.com website.

 

So questions:

 

1) When you access this website, could you please check the certificate to find out what the CN or SNI is?

 

2) Do you have SSL Deep Inspection applied?

Regards,

Jerry
Laniver

The website is an internal facing website.

We are doing SSL certificate inspection using our own internal CA cert.

 

dingjerry_FTNT

Hi @Laniver ,

 

Do you know what the SNI is in the client Hello?  If you don't know, you may capture the packets using software, like WireShare to check.

 

What is the CN of your own internal CA cert?

Regards,

Jerry
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors