Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jasonhilt
New Contributor

Opera Mini browser iPhone

Anyone know how to block this from bypassing our web filter?  We have a 1240B running 5.0,build0310 (GA Patch 11).

Opera Mini completely bypasses all filtering and allows access to porn, which is unacceptable on a school network.

 

2 REPLIES 2
jintrah_FTNT
Staff
Staff

Hi,

 

It is better to block the opera mini application itself from being used. Opera mini may use its own port and encryption to contact opera servers to provide better browsing experience for end user.  A use of app control/ ips signature ("HTTP.BROWSER_Opera.Mobile")  can  be used to control/block the traffic. Have ssl deep inspection enabled in the firewall policy and  also allow only standard ports 80/443 for web traffic.

 

Regards,

 

 

nbctcp
New Contributor III

If using Mikrotik here the rule. I want to know how to convert it into fortigate

Mikrotik: /ip firewall address-list add address=12.12.12.0/24 list=LAN /ip firewall layer7-protocol add name=opera regexp="^.+(opera-mini.net).*\$" /ip firewall filter add action=drop chain=forward layer7-protocol=opera src-address-list=LAN
http://goo.gl/lhQjmUhttp://nbctcp.wordpress.com
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors