Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
F-ALI
New Contributor III

Issue with Blocking YouTube and Affecting Google Docs

Hi everyone,

I’ve configured my FortiGate to allow access to Google Docs only for certain users. However, I noticed that those users were still able to access YouTube.

Upon investigation, I found that Google Docs and YouTube share some of the same IP addresses, which makes it difficult to block one without affecting the other.

When I created a policy to block YouTube, it ended up blocking Google Docs too.

Has anyone found a way to allow Google Docs while effectively blocking YouTube?

 

Any suggestions would be appreciated.

 

youtube_IP.png

6 REPLIES 6
AEK
SuperUser
SuperUser

Hi Ali

Don't use FQDN for that. Use ISDB as destination address instead.

AEK
AEK
F-ALI
New Contributor III

Hi AEK ,

thanks for your input , but after check the internet service list , there's no service for YouTube

ISDB.png

F-ALI
New Contributor III

Any suggestions would be appreciated.

AEK

My bad. Use app control instead to block YouTube application.

AEK
AEK
F-ALI
New Contributor III

Hi AEK,

Thanks for your suggestion. I gave it a try, but it wasn't effective in this case.

As a temporary solution, I applied traffic shaping rules to limit YouTube traffic to 200 Kbps per IP.

With this in place, Google Sheets is now accessible, although YouTube videos load very slowly due to the reduced bandwidth.

Additionally, I plan to block YouTube entirely by mapping www.youtube.com to an invalid IP address in the hosts file or via a custom DNS record on our DNS server.
This should effectively prevent access by resolving the domain to an incorrect address.

ArminF
New Contributor

Got the same issue. Wanted a dedicated web profile with App,DNS, etc filters.
But the ISDB routes youtube.com and googlevideos.com into the Google Gmail collection.
As soon as i remove the Google Gmail it works but then routes all google meet, mail traffic through my default web police with all the filters applied. 
Is there are possiblity to overwrite those ISDB ranges maybe?


Thanks

Forti 71G Home Protection
Forti 71G Home Protection
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors