Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tuan2tech
New Contributor III

How to block adult website

Hi you

I'm trying to block adult websites using Fortinet's Web Filter. I've already blocked the "Adult/Mature Content" category in the Web Filter profile. Additionally, I've added URL Filter and Content Filter rules using a wildcard for the keyword "vlxx" (e.g., *vlxx*), which is a known adult site.

However, the website is still accessible. I checked the logs and saw that the traffic is going through Cloudflare, and it is not being blocked by any of the configured filters.

Could someone please help me understand why this is happening and how to effectively block this site?

Thanks in advance for your support.

 
  1. 1.0.jpg1.2.jpg1.1.jpg
4 REPLIES 4
yderek
Staff
Staff

@tuan2tech  

The logs showing cloudfare CDN which might be the first hop when website has been visit 

Can you paste the entire firewall policy in this post ? 

show full firewall policy 115

Also, what type of the SSL inspection are you using ? Deep inspection or flow based inspection ? 

Do you use application control in the firewall policy ? 

tuan2tech
New Contributor III

Hi @yderek 

 

Thanks for supporting me, i send the rules details as below image, i only use based inspection

 

policy-1.jpg

yderek
Staff
Staff

@tuan2tech  

Can you please try the  below method 

 

1: In the browse address bar, if you are using chrome, type chrome://flags/, find QUIC and disable this flag , use private window and try again from there 

2: I can see you are using the web filter and DNS filter, can you try to use the application control with adult category block and use the deep inspection in firewall policy and try again  ? 

Please create the test policy with single IP address only affecting any production impact

3: If you are using the deep inspection, you might need to install the certificate that apply in the deep inspection to your computer , you can use the default system deep inspection, I screenshot for your reference, download that certificate and install on your test computer root chain to avoid certificate error 

4: If that still not working , right click the adult page and choose inspection , check the network part and refresh the page, download the har file upload here 

 

Screenshot 2025-05-09 143911.jpg

tuan2tech
New Contributor III

Thanks for your help:
1. I did chrome but nothing changed
2. I blocked category both in DNS and webfilter but no success
3. I didn't use deep inspection

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors