- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Fortigate firewall static URL not exempting URLs from web filter
The firewall is running version 7.2.10.
I have a set of rules which has web filters, IPS and DNS filters enabled.
The web filter is set to warning for unrated websites. I have set several static URL filters to exempt certain URLs from web filtering, but it is apparently still being blocked by web filtering.
How do I ensure the static URL filters work for exempting URLs from web filtering?
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Laniver ,
When you say "but it is apparently still being blocked by web filtering", did you mean it is blocked by the FortiGuard Category?
Anyway, can you share your URL Filter configuration for the URLs in this issue?
Jerry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Laniver,
When apparently blocked by web filtering so at time if you encounter a FortiGuard Deny Page due to web filtering, please provide a screenshot of the page.
Additionally, navigate to Log & Report -> Security Events -> Web Filter in your system and review the logs details on whether the website was blocked or bypassed. Pay attention to the "Message" field in the logs as well.
Note: To exempt a specific website, use the Wildcard type for the exemption.
You can refer to the below document for Troubleshooting static URL filter by 'debug ips'
Regards,
Aman
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please see attached image when I set web filter to 'Warning' for unrated category.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Laniver ,
The log message does not help us to identify why FortIGuard Category blocked it.
Please provide your static URL Filter configuration about "anw.cz.com".
Jerry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Static URL filter configuration:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks, but I noticed it does not work for all cases.
For instance, *anw.cz.com* does not match xc03.anw.cz.com.
I have another matching issue which I am having trouble with.
Domains to be matched:
c1-ny-cvx.anw.cz.com
c1-ny-mpm.anw.cz.com
I created the following regular expression, but it does not match. Traffic to both domains still get denied by the web filter.
c1-ny-(cvx|mpm)\.anw\.cz\.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Laniver ,
Could you please share your new URL filter configuration?
And are those URLs HTTPS-based?
Jerry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, they are HTTPS based.
