ORIGINAL: ejhardin Not possible with a fortigate... This is way I still have my ISA server.Wait, why not? Couldn' t you SSL offload to the FGT, and use URL filtering?
Wait, why not? Couldn' t you SSL offload to the FGT, and use URL filtering?Maybe... I don' t have a device that will do VIP SSL Offloading. 7bits stated that he has a 60c and I don' t believe that the 60c has the ability to VIP SSL Offload.
Has anyone been able to resolve this issue or do we have to look at a different firewall product?
to be able to do url filtering with https you have to have ssl deep inspection enabled on the policy.
Then make one policy that hits trtaffic to the server and set an urlfilter that only allows those two paths.
Maybe it is a good idea to create those as wildcard rules. Set the action to exempt instead of allow.
Then create a third rule that blocks everything. This one must be the last rule.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.