Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
bucky23
New Contributor

URL Filter not blocking sites 60F

I have a Web Filter security profile already in place. Along with AV, DNS, APP, SSL filters as well. I am trying to add a site to URL filter for it to be blocked. I got this to work at one point by selecting Wildcard, Block, Enable. I had it written as *.website.com and it seemed to work hit or miss (seems like if you cleared your cache and retried it would give you the blocked splash page when trying to access the site). I am trying to block a website now and it will not block no mater what I do. Same for the old site that originally DID get blocked. I have the security profiles all set up as they should be and they haven't been touched. Why is this not working? 60F version 7.2.9

 

 

7 REPLIES 7
dingjerry_FTNT

Hi @bucky23 ,

 

1) What is the URL you are going to block?

Is it HTTPS based?  Is it HSTS based?

 

2) How did you configure the URL Filter entry for this URL?

 

3) Do you use Certificate Inspection or Deep Inspection?

Regards,

Jerry
bucky23

1) deepseek.com

 

2) I've tried 5 different variations on the URL filter for the naming convention. Lets start with *.deepseek.com because that's what I have it as now

 

3) I am using Full SSL Inspection

 

I should also mention that even when I change a FortiGuard Category to blocked it doesn't even block! I have the FortiGuard Categories all set to Custom, All are "monitor" except obvious ones that need to be blocked for a work environment. 

dingjerry_FTNT

Interesting. I am using the format you provided for the URL Filter entry and I got blocked:

 

dingjerry_FTNT_0-1738611559120.png

 

Regards,

Jerry
kwcheng__FTNT

If you are using Full SSL inspection, you might want to check the exclusion list under the SSL profile. Security scanning will be excluded when it is fallen under "Exempt from SSL Inspection" configuration.

Do you need to configure a static route when passing an apple from left hand to right hand?
bucky23
New Contributor

Looks like the block is working on Firefox and Edge. But Chrome is holding strong even after deleting cache. I also cannot get masters.com to be blocked on anything. I have that set up as the same naming convention *.masters.com

dingjerry_FTNT

Hi @bucky23 ,

 

I tested it again with masters.com, it still worked for me with both HTTP and HTTPS:

 

dingjerry_FTNT_0-1738622361268.png

 

Regards,

Jerry
kwcheng__FTNT

This could be a bug issue, you can initiate a TAC ticket

Do you need to configure a static route when passing an apple from left hand to right hand?
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors