Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ISOffice
Contributor

Is this normal??

Hi all,

 

I thought I would just share a recent experience we had with our FortiGate 100D Cluster (Active-Active), Version 5.2.1 Build 618.

 

I had created and applied a Web Filter Profile (let's call it Profile No1) to a particular group of users. I then cloned this Web Filter Profile, made a few changes to the cloned profile (imaginatively named Profile No2) and applied it to a second group of users.

My reason for two separate Web Filter Profiles was I wanted to impose slightly different Static URL Filters to each profile.

 

However, I noticed when I made a change to the Static URL Filter in either Web Filter Profile it immediately appeared in the other profile (wether I wanted it to or not). This had me confused as I imagined that the Web Filter Profiles were completely separate from each other.

 

I dug around in the configuration and found that in the config webfilter urlfilter section, a urlfilter called 'DefaultWebFilter' had been created. I also noticed that in the config webfilter profile section, sub-section config web was a setting, set urlfilter-table n (n = number assigned to DefaultWebFilter urlfilter).

 

I then was able to create a new webfilter urlfilter and assign the relevant Web Filter Profile to it and my problem disappeared.

 

I just wanted to know if anyone else has experienced this sort of behaviour and is it as a result of cloning existing profiles rather than creating them from scratch?

 

Hope this makes sense!!

 

Best regards,

 

JP

1 Solution
rwpatterson
Valued Contributor III

Sounds like a bug in the GUI. I would put in a ticket.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

View solution in original post

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
6 REPLIES 6
rwpatterson
Valued Contributor III

Sounds like a bug in the GUI. I would put in a ticket.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
ISOffice
Contributor

Cheers Bob!! Might just do that.

 

I just thought it strange that the clone facility, while generally helpful, can cause some minor headaches. Best practice for now will be, create any new Web Filter policies from scratch. Wonder if it applies to Application Control, Intrusion Prevention etc. policies as well.

 

Thanks again,

 

JP

Dave_Hall
Honored Contributor

This also happens on 5.0.x (7/9).  But I personally do not see it as a bug, but more of an oversight on Fortinet's part (in not informing us) that the underlying URL filter list is not also cloned.  Checking the max value table, you are limited on the number of URL filter lists created vs Web filter profiles.  Although none of our Fortigates are nowhere near the max limit (web filter profiles vs URL filter lists), I can see someone running into this hard-coded limit on the mid-higher-end fgts.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Matthew_Mollenhauer
New Contributor III

I'd agree with Dave in that this isn't so much a bug but rather an unintuitive UI.

 

When you break it down to the simplest terms the Web Filter Profile is simply an object as is the URL Filter. So you have Object A referencing Object B, cloning Object A will clone the reference not the Object referred to.

 

Consider when you clone an Address Group, do you expect that the Addresses that are members of the group to also be cloned?

 

Regards,

Matthew

ISOffice
Contributor

Hi Dave & Matthew,

 

Many thanks for your input. I agree that it's more of a minor nuisance than an actual bug. I'm just getting into the FortiGates and find that as each day goes by, I learn a little bit more. Very impressed overall with the product, just wanted to share the experience.

 

Best regards,

 

JP

ISOffice
Contributor

Hi All,

 

I submitted a ticket to FortiNet on this issue and their reply was....

 

"...managed to reproduce the same behavior and it seems that this is the expected behavior when cloning existing Web Filter profile. However we have already informed the development team about this and they are looking to make a change in the future release. Unfortunately, until then you will need to make the change from the CLI."

 

Best regards,

 

JP

Labels
Top Kudoed Authors