Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Phillyidol
New Contributor

HTTPS Block - ONLY YouTube

Okay - forgive me if this has been asked and answered, as I have some fair experience with firewalls, but a newbie with FortiGuard, so looking for some ' step-by-step' instructions that cover a larger range of these units, as we have one 80C, and one 100D, both with v5.0 FW. Issue is we put together a rule to block youtube, but no matter what settings we try (including the SSL Inspection settings, which BTW look like they are ONLY for a Proxy setup with a Web Filter), we can' t seem to block youtube with an https in the URL. As mentioned, if anyone has the FULL steps/settings to get this to work, it' d be greatly appreciated. Again, apologies if this was answered, but I looked and only found references of steps and looking for all steps, although, I just may have missed the post. Thanks
Philly Idol
Philly Idol
12 REPLIES 12
Phillyidol
New Contributor

P.S. We tried some settings, but it blocked ALL https URL' s, and as the title of the post says, we ONLY want to block https for youtube
Philly Idol
Philly Idol
FortiAdam

Welcome to the Forums Phillyidol! Since it seems like you are relatively new to webfiltering on the Fortigate I' m going to direct you towards the Fortigate Cookbook here http://docs.fortinet.com/uploaded/files/359/fortigate-cookbook-507-expanded.pdf . Fortinet also made a pretty helpful video on how to accomplish something what you are trying to do http://video.fortinet.com/video/124 . If you' re still having problems after check that out let us know a few more specifics about your setup and we would be glad to help!
Phillyidol
New Contributor

Hello FortiAdam, Thanks for the reply and the warm welcome. As to the cookbook and video, I' ve gone through them both (thanks for those), and the problem is we' re actually working with two different FortiGuard units (I was just informed that there were two locations we had to set this rule up on) Basically now the fun has really begun, because the one unit is an 80CM, with firmware v4.0-MR3 patch 14, and the other (which is the 100D I was initially working with) has firmware v5.0, but the [GA] release, which apparently removed the ' SSL/SSH Inspection' option from the ' Policy' objects. I' ve never worked with an 80CM v4.0 unit before, so that one' s a new experience, but now the 100D has options missing that we' re on other 100D' s that I' ve serviced. Needless to say, my tasks just got a whole lot more interesting, so if you have any ' go here' >create this>add to that' instructions for either unit type, would be much appreciated. Of course I' m still digging through the cookbook and videos myself, so I' ll definitely drop in what I ended up doing to get t to work. Thanks much
Philly Idol
Philly Idol
Phillyidol
New Contributor

P.S. They client really doesn' t want to do the, " install Fortigate' s security cert. on all the workstations" with the deep inspection route, so I' m trying to avoid that as much as possible. I just can' t see that there' s no way to create a simple enough rule to block a single site with both http and https instead of a major rule that blocks all https. Seems kind of backward to me. Anyway, thanks again for any assist
Philly Idol
Philly Idol
TuncayBAS
Contributor II

In fact, as is done in V5, prohibitions over https easier. Step 1: Step 2: Step3: Step 4:

Tuncay BAS RZK Muhendislik Turkey NSE 4 5 6 FCESP v5

Tuncay BAS RZK Muhendislik Turkey NSE 4 5 6 FCESP v5
Phillyidol
New Contributor

Wow! Thanks yaba, that was awesome of you. I' ll fire through the settings and see what happens. Just as an FYI to you, or anyone else who reads this. Just got off the phone with another FortiNet/Guard guy and he said it may be because the 100D firmware is at the [GA] patch level, which is actually 5 patch versions behind, and he said patch 2 or 3 corrected some of the filter issues. Anyway, I' ll see where I get with those settings and let you know. Thanks again
Philly Idol
Philly Idol
FortiAdam

He also should have told you that the version of code you' re running is vulnerable to heartbleed. If you have an SSL VPN or if you' re administrator login page is available on the internet you should consider upgrading ASAP! Yaba did an excellent job explaining what to do with his screenshots. Just make sure you either block the streaming media category or you follow the category override video and reclassify youtube to a denied category. You will need fortiguard categories enabled and a valid subscription to the fortiguard service. When you go to do this on your v4 80cm the process might be slightly different as I know they developed SSL inspection quite a bit in v5. We might need to consult in someone that is more familiar with v4 to determine the exact configuration. I would encourage you to explore some of the older posts and you will find that there has been a lot of discussion regarding blocking of HTTPS sites.
TuncayBAS
Contributor II

Thanks Phillyidol

Tuncay BAS RZK Muhendislik Turkey NSE 4 5 6 FCESP v5

Tuncay BAS RZK Muhendislik Turkey NSE 4 5 6 FCESP v5
sandeep_kumar
New Contributor

dear please use application sensor for to prevent to access https
sandeep kumar IT Executive
sandeep kumar IT Executive
Labels
Top Kudoed Authors