Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

How to filtering traffic if Using Explicit Proxy

Dear All, We use Fortigate unit as Explicit Proxy at our customer. But we have some problem when PC client used IP proxy fortigate the PC client can' t filtering by the unit, so the traffic going passtrough. Even if we not create firewall policy from internal port to internet port the PC Client traffic still going passtrough. How we filtering traffic from internal to internet if we using explicit proxy? Please suggest.
17 REPLIES 17
Not applicable

Are you using VDOMs on this Fortigate? If you are using the explicit proxy and trying to utilize a protection profile on that traffic, they must be in different VDOMs.
flppds
New Contributor

I have a similar problem: I tried to use 2 VDOM , VDOM1 to act as a explicit proxy and VDOM2 that apply Protection profiles. My problem is that I have different protection profiles for different user groups, and I cannot filter urls for example, because all requests are coming from the IP address of the explicit proxy. Now I am trying to use one VDOM1 in trasparent mode, to filter URL requests from users, then with an external cable connect to VDOM2 in NAT mode, that act as explicit proxy. I configured protocol recognition on port 8080 to use Fortinet Web Filtering with the url requests toward the proxy. Currently I am struggling to configure FSAE for correct user identification!
Not applicable

Thanks guys, I try to using 2 VDOMs and its work. Regards, Taufik
flppds
New Contributor

Hi, someone has tryed the new OS 4.0 MR2 that should fix this problem, and allow to do explicit web proxy and also web filtering, antivirus in just 1 VDOM?
red_adair
New Contributor III

Yes, in 4.2 you get a " virtual Interface" and you basically write a FW Rule from Web-Proxy(IP-Range) -> WAN(IP-Range) Than you can apply AV or Web-Filter or user-auth to this Policy (No IPS or App-Ctrl yet). -R.
ejhardin
Contributor

But the question is has anyone tried it... I' m on 4.2 and no it does not work. I have another ticket in with fortinet. (Mostly a bug... what a shock)
Shahzadjeelal
New Contributor

omeone has tryed the new OS 4.0 MR2 that should fix this problem
Yes, i had tested this in my setup, its work very well with UTM features. But when i use identity based policy for web proxy interface. facing number of problem listed below. 1. The green color login page gone & its show NTLM type login page. 2. User monitoring not shows authenticated users. 3. Authentication timeout setting is not getting effected for wen proxy policy. mean very time when i open new browser its asking for authentication. 4. Frequently getting " 504 dns lookup failed" banner page. 5. IPS & App control UTM features are not applicable. 6. LDAP group extraction is not working with web proxy. Guys, Share your experience with MR2. Shahzad
Thanks & Regards, Siddique Siddique Technical Consultant
Thanks & Regards, Siddique Siddique Technical Consultant
ejhardin
Contributor

How did you configure the web-proxy settings and the firewall settings? Also are you using switch-interface. I have configured the web-proxy and know that it is working because if I enable the allow default firewall policy then I' m able to access the internet but this settings does not apply any utm protection. I have created a policy with the web-proxy as the source. It seems like the web proxy is not reading the firewall policy and I believe that it has to do with the switch-interface settings. Any ideas?
Shahzadjeelal
New Contributor

configuration steps: 1. enable web proxy on interface 2. go to web proxy tab & configure required settings. (Deny) Default Firewall Policy Action. 3. Create policy between Web Proxy (Logical interface > external interface. Enable identity based policy session base not IP based. Note: In my setup , i was using fortigate 310-B, which is by default running on interface mode only.
Thanks & Regards, Siddique Siddique Technical Consultant
Thanks & Regards, Siddique Siddique Technical Consultant
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors