Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Goatrman
New Contributor

Issue blocking Youtube

Fortigate 80C Firmware 5.0

 

I am having an issue trying to block youtube.com. 

[ul]
  • I have the web-filter subscription.
  • I have edited the Web filter profile to block all "Bandwidth consuming" sites (Streaming ect)
  • Enabled website filter, *Youtube.com / Wildcard / Block / Enable. [/ul][ul]
  • I have added Web filter to my policy for my network. (Internal 2 - WAN 1) 
  • I rebooted the Fortigate to ensure all sessions were stopped, so this could take effect. [/ul]

    People on the network are still accessing Youtube.

     

    Still no luck, Any assistance would be appreciated. 

     

  • Fortigate 80C FW 5.0

    Fortigate 80C FW 5.0
    1 Solution
    Dave_Hall

    "Deep packet" inspection needs to be enable on the firewall policy covering "web traffic" - otherwise "blocking" just by web/URL filter (via security certificate inspection) may/will not work (because youtube uses Google's *.wildcard security certificate).  

     

    If Application Control does not work and you can not use "Deep packet" inspection then you could try blocking direct access to the main fqdn addresses via firewall polices - IMO it's "ugly" but does work to a certain extent. YMMV.

     

    Another option would be to use DNS web filtering.

    NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

    View solution in original post

    NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
    4 REPLIES 4
    Toshi_Esumi
    SuperUser
    SuperUser

    URL based blocking probably wouldn't work well. Try using Application Control instead like below. Also we have Application Control Forum about it where you can search more.

    http://cookbook.fortinet....-youtube-applications/

    Dave_Hall

    "Deep packet" inspection needs to be enable on the firewall policy covering "web traffic" - otherwise "blocking" just by web/URL filter (via security certificate inspection) may/will not work (because youtube uses Google's *.wildcard security certificate).  

     

    If Application Control does not work and you can not use "Deep packet" inspection then you could try blocking direct access to the main fqdn addresses via firewall polices - IMO it's "ugly" but does work to a certain extent. YMMV.

     

    Another option would be to use DNS web filtering.

    NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

    NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
    Goatrman

    Toshi and Dave, Thanks for the responses, I will try these suggestions and report back with my results.

    Fortigate 80C FW 5.0

    Fortigate 80C FW 5.0
    shah_nawaj

    Hi,

     

    Good day!!!

     

    Tried DNS Filtering, bandwidth consuming, and blocked streaming Media and download, Now no more you tube in our network.

     

    Thanks for support,

     

    Shah

    Announcements

    Select Forum Responses to become Knowledge Articles!

    Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

    Labels
    Top Kudoed Authors