Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
JerryPWhite1
New Contributor II

Not really sure where to start.

I have gone through the initial setup of my new 800C. Can't seem to understand the way this device uses security policies. For starters, I want to use a web filter to block all websites to the default user profile. The options inside the web filter are proxy, flow-based, and dns. I have read that proxy based is the most secure. Do I need to setup an explicit proxy for this to work? I have so many other questions but support tells me they won't help unless there is a problem.

Jerry Paul White

Network Engineer/Tech Supervisor

" 01001000 01100001 01110110 01100101 00100000 01100001 00100000 01000111 01101111 01101111 01100100 00100000 01000100 01100001 01111001"

Jerry Paul White Network Engineer/Tech Supervisor " 01001000 01100001 01110110 01100101 00100000 01100001 00100000 01000111 01101111 01101111 01100100 00100000 01000100 01100001 01111001"
6 REPLIES 6
Bromont_FTNT
Staff
Staff

 

You don't need explicit proxy for proxy based filters. How are you identifying your users for the filters? LDAP/AD? IP?

JerryPWhite1
New Contributor II

Right now it's just by ip address for testing. Once I put it into production I will want to join it to the domain.

Jerry Paul White

Network Engineer/Tech Supervisor

" 01001000 01100001 01110110 01100101 00100000 01100001 00100000 01000111 01101111 01101111 01100100 00100000 01000100 01100001 01111001"

Jerry Paul White Network Engineer/Tech Supervisor " 01001000 01100001 01110110 01100101 00100000 01100001 00100000 01000111 01101111 01101111 01100100 00100000 01000100 01100001 01111001"
JerryPWhite1

Any help would be greatly appreciated.

Jerry Paul White

Network Engineer/Tech Supervisor

" 01001000 01100001 01110110 01100101 00100000 01100001 00100000 01000111 01101111 01101111 01100100 00100000 01000100 01100001 01111001"

Jerry Paul White Network Engineer/Tech Supervisor " 01001000 01100001 01110110 01100101 00100000 01100001 00100000 01000111 01101111 01101111 01100100 00100000 01000100 01100001 01111001"
KM_FTNT
Staff
Staff

Fortinet has a video guides site where they post goo technical video showing how to setup various features.  They have few on setting up Web Filtering security profile, here is the latest one: http://video.fortinet.com/video/115/basic-web-filtering-5-2

 

I suggest you go to video.fortinet.com and have a look at few videos to understand how it all works.

 

hope this helps.

 

Technical Video - video.fortinet.com

Technical Docs - docs.fortinet.com

 

Dave_Hall
Honored Contributor

@jpwhite

 

See this post.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
JerryPWhite1
New Contributor II

Part of my issue was the latest update 5.2.2. I created a ticket and an engineer had me downgrade to 5.2.1. This resolved my issue. To begin with my issue was that I could not apply a web filter in proxy mode. It would not work at all.

Jerry Paul White

Network Engineer/Tech Supervisor

" 01001000 01100001 01110110 01100101 00100000 01100001 00100000 01000111 01101111 01101111 01100100 00100000 01000100 01100001 01111001"

Jerry Paul White Network Engineer/Tech Supervisor " 01001000 01100001 01110110 01100101 00100000 01100001 00100000 01000111 01101111 01101111 01100100 00100000 01000100 01100001 01111001"
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors