Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kenjiak
New Contributor

How to configure a network to block all website but just allow google apps mail?

How to configure a network to block all website but just allow google apps mail loads via https://mail.google.com/a/[domain] and gmail loads via https://mail.google.com/mail on my environment is using FortiOS v5.2.10 ?

 

My device is using Fortigate 60D

 

2 REPLIES 2
sw2090
SuperUser
SuperUser

Create a webfilter security profile (or use the defaut one that already exists if you want) and enable the static url filter in it. Then make three rules:

 

1. Allow https://mail.google.com/a/* by Exempt

2. Allow https://mail.google.com/mail by Exempt

3. Block everything else (i,e, block *)

 

Then keep the rules in this order (you may exchange 1. and 2. but the block everything rule must be the last one).

Also you have to use "exempt" and not "allow" because you want the filter to stop once one rule allowed access to the site. Without "exempt" it would block everything even though there is 1. and 2. because it won't stop.

 

Once you are done with that save your profile and apply it as webfilter profile to your wan policy(s) for that network.

 

then you are done :)

 

hth

Sebastian

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
makco10

Hello,

 

Thanks sw2090, this works for me:

 

 

 

Regards.

Defend Your Enterprise Network With Fortigate Next Generation Firewall
Defend Your Enterprise Network With Fortigate Next Generation Firewall
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors