I am using FortiManager v7.6.2 build 3415 (Feature)
I would like to block a website named scribd.com .
I created url filter and profile under Policy & Objects > Advanced > webfilter> Profile > Create Profile (name Office URL) - attached ID 14 under - Web > Urlfilter-table > ID 14
then I created url filter under Policy & Objects > Advanced > webfilter > urlfilter > Create ID > 14 > block as ( *.scribd.com < wild card.
Then I attached these under Policy & Objects > Policy Packages > FG Traffic > Office Traffic > Webfilter > attach Office URL profile .
There are no rules above on the Office Traffic.
The SSL method currently using is -
named : no inspection - but - Inspection Method is Full SSL Inspection
CA Cert : Fortinet_CA_SSL
I did Install Wizard under Device manager and choose FG Traffic
I do have License for Webfilter I cleared cache but still cannot block the web page.
Should I change the SSL no-inspection to custom-deep-inspection
OR
One thing I notice after check with ChatGPT is - when I open the website scribd.com and check for certificate issuer - it's saying ( Let's encrypt - instead of Fortinet_CA_SSL ) .
Should I force client PC to use Fortinet_CA_SSL
Please suggest.
Thank you.
You can't do Web Filtering with SSL no-inspection.
You need at least certificate-inspection.
In your case you don't need deep-inspection.
thanks AEK,
Yes, this is my confuse part : when I click on SSL Inspection and edit,
what I see is the name is " no inspection - read only profile" but below its' Inspection Method is "Full SSL Inspection"
Should I leave as this or I should change to " custom-deep-inspection"
OR
As there is CA-Cert set to Fortinet CA SSL - should I install that cert to all the client?
Thank you
The read-only no-inspection profile doesn't inspect traffic neither certificate. I think this is a display error.
You should use the Certificate-Inspection or just create your own. You don't need deep inspection and so you don't need to install any CA certificate on clients.
User | Count |
---|---|
2571 | |
1365 | |
796 | |
653 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.