Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Carneno
New Contributor

How do we allow certain users in a blocked URL Filter?

[size=3] Hello, We have a FortiGate 50B with firmware: v4.0,build0521,120313 (MR3 Patch 6). protecting a Windows 2008 R2 server. I have blocked some web sites using UTM Profiles > Web Filter > URL Filter. Is there a way to allow certain users to override/bypass the block for one specific URL? Any help would be gratefully appreciated. Thanks, Tony [/size]
Stop The World, I want To Get Off!
Stop The World, I want To Get Off!
8 REPLIES 8
Carneno
New Contributor

[size=3] Is this forum broke? Or is there just nobody that has answers? Thanks, Tony [/size]
Stop The World, I want To Get Off!
Stop The World, I want To Get Off!
rwpatterson
Valued Contributor III

This forum definitely isn' t broke. I guess no one has an answer for you. :(

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
billp
Contributor

Is there a way to allow certain users to override/bypass the block for one specific URL?
If I understand you correctly, this is called Administrative Override. It' s available in the GUI in MR2 under the Webfilter menu item. In MR3, they changed the implementation and it' s only available in the CLI. It' s in the docs as " Web Filtering Overrides." According to the docs, you need to create a special profile that allows the website in question and you can then assign that override profile to specific users. It' s much simpler in MR2.

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
Carneno
New Contributor

Hello Bill. Thanks for your help. According to the documentation, you can connect to the CLI locally or through the network. If we login to the Fortigate by bringing up IE and putting an IP address in the address field and logging in with an administrator and password, does that mean we are connecting through the network? Thanks, Tony
Stop The World, I want To Get Off!
Stop The World, I want To Get Off!
billp
Contributor

Tony, The way you described is the " local" way. What they mean is that you can login to the GUI and click on the " CLI Console" widget to get access. Or, if you have an SSH client, you can login directly to the CLI that way, assuming you' ve granted SSH access when you set up the firewall. Fortinet has a lot of great features, but they require some tinkering to get working. It' s not a Sonicwall which is entirely GUI driven (I believe). With Fortinet, the GUI is more like the tip of the CLI iceberg. I have used Administrative Overrides frequently in MR2, but the setup in MR3 is different. So not sure I can offer much practical advice. From what I' ve read, you need to create a new webfiltering profile (in the GUI) and call it something like OverRideUsers. In that profile, remove the restriction for the website you want unblocked. Then, in the CLI, you tell it that users in CurrentProfile should have the OverRideUsers profile if they are listed in a special group, or have a specific user ID. I' ve attached the relevant part of the manual in case you weren' t able to find it earlier.

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
michellem812
New Contributor III

We' re on 1240B 4.3.6 and I can confirm that setting up an override is a lot more up-front work-intensive on the admin, since it now involves creating a separate policy for the override group. I had the Fortinet tech work with me on this to be sure I was understanding correctly. https://fortinet.webex.com/fortinet/ldr.php?AT=pb&SP=MC&rID=53850562&rKey=c8e281ef 606f6140 is the saved webex video describing the differences in the older way of doing overrides and the newer way of doing overrides. (I can' t get the link to paste right, so be sure to copy/paste including the 606f6140 number in the link.) With this new way, I wish there was a way to copy an existing policy to a new one, so it' s easier to just tweak the pieces you need, instead of going through each category one by one and setting up almost identical, then tweaking it. I did test this partially successfully - it works as intended if you use Firewall auth or possibly AD auth. However, using FSSO eDirectory authentication, there is a known bug that will be fixed in the next upgrade that will allow it to work with FSSO eDirectory usernames (apparently the CN=Name... format is throwing it).[link=][/link][link=][/link]
cmberry
New Contributor

4.3.6 has fixed the bug related to Admin Override for blocked url categories. I have confirmed this myself on my 200B. You simply need to go into the webconfig then: UTM Profiles>Web Filter>Profile>[then select your profile from the drop down on the top right]>expand the categories, place a check mark on the category you want to allow overrides, and then change the " Action" to " Authenticate" . This will thow up a window to select which users groups you want to allow. I have a group setup called " override" . Hit Apply, and then wait a few seconds, and them test an appropriate URL. For instance, I am blocking social networking, but allow overrides, so I test with facebook.com, which will then add a button the the blocked site to enter a username and password. On former patches, it broke your ability to get past the block message, even when the category was setup correctly.
blaszta
New Contributor

How about just create another policy for that particular user/group and put it on top of the current policy?
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors