Hi all,
I thought I would just share a recent experience we had with our FortiGate 100D Cluster (Active-Active), Version 5.2.1 Build 618.
I had created and applied a Web Filter Profile (let's call it Profile No1) to a particular group of users. I then cloned this Web Filter Profile, made a few changes to the cloned profile (imaginatively named Profile No2) and applied it to a second group of users.
My reason for two separate Web Filter Profiles was I wanted to impose slightly different Static URL Filters to each profile.
However, I noticed when I made a change to the Static URL Filter in either Web Filter Profile it immediately appeared in the other profile (wether I wanted it to or not). This had me confused as I imagined that the Web Filter Profiles were completely separate from each other.
I dug around in the configuration and found that in the config webfilter urlfilter section, a urlfilter called 'DefaultWebFilter' had been created. I also noticed that in the config webfilter profile section, sub-section config web was a setting, set urlfilter-table n (n = number assigned to DefaultWebFilter urlfilter).
I then was able to create a new webfilter urlfilter and assign the relevant Web Filter Profile to it and my problem disappeared.
I just wanted to know if anyone else has experienced this sort of behaviour and is it as a result of cloning existing profiles rather than creating them from scratch?
Hope this makes sense!!
Best regards,
JP
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Sounds like a bug in the GUI. I would put in a ticket.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Sounds like a bug in the GUI. I would put in a ticket.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Cheers Bob!! Might just do that.
I just thought it strange that the clone facility, while generally helpful, can cause some minor headaches. Best practice for now will be, create any new Web Filter policies from scratch. Wonder if it applies to Application Control, Intrusion Prevention etc. policies as well.
Thanks again,
JP
This also happens on 5.0.x (7/9). But I personally do not see it as a bug, but more of an oversight on Fortinet's part (in not informing us) that the underlying URL filter list is not also cloned. Checking the max value table, you are limited on the number of URL filter lists created vs Web filter profiles. Although none of our Fortigates are nowhere near the max limit (web filter profiles vs URL filter lists), I can see someone running into this hard-coded limit on the mid-higher-end fgts.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
I'd agree with Dave in that this isn't so much a bug but rather an unintuitive UI.
When you break it down to the simplest terms the Web Filter Profile is simply an object as is the URL Filter. So you have Object A referencing Object B, cloning Object A will clone the reference not the Object referred to.
Consider when you clone an Address Group, do you expect that the Addresses that are members of the group to also be cloned?
Regards,
Matthew
Hi Dave & Matthew,
Many thanks for your input. I agree that it's more of a minor nuisance than an actual bug. I'm just getting into the FortiGates and find that as each day goes by, I learn a little bit more. Very impressed overall with the product, just wanted to share the experience.
Best regards,
JP
Hi All,
I submitted a ticket to FortiNet on this issue and their reply was....
"...managed to reproduce the same behavior and it seems that this is the expected behavior when cloning existing Web Filter profile. However we have already informed the development team about this and they are looking to make a change in the future release. Unfortunately, until then you will need to make the change from the CLI."
Best regards,
JP
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.