Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
networkingkool
New Contributor

Understanding Web Filtering !!!

Hi forum, I ' m trying to use Web filtering feature include URL Filtering and Fortiguard Categories. First, I BLOCK all New and Media category in working hours, It work well. Then I ALLOW only some news webs in URL Filter list, but It does not work as I expected. Those websites still blocked by Fortiguard category. I check the Fortigate document and see the web filtering order: 1.URL filter 2.FortiGuard Web filter 3...... 4.... 5.Antivirus Scan I ' m sure that I do not enable strict blocking. My fortigate use OS 5.0 GA patch1. Can anyone tell me whether I lack some config to achieve my goal?
=========>
=========>
5 REPLIES 5
rbenassi
New Contributor

Did you create a custom category and joined the url to custom category from the UTM Security Profiles -> Web filter -> Rating Overrides menu ? The custom category has to be set as allowed in your web filtering profile. I hope this helps you.
networkingkool
New Contributor

Yes! Thanks to your reply. I used Rating Overrides settings, and it works well. But I do not understand the process order of web filtering. I read this sentence in Fortigate document " Any attempt to access a URL that matches a URL pattern with an allow action is permitted. The traffic is passed to the remaining antivirus proxy operations, including FortiGuard Web Filter, web content filter, web script filters, and antivirus scanning." First I allow that specific URL in URL Filter list, then I block that URL' s category by Fortiguard Category. Then the URL is blocked by Fortiguard Category. It does not go as the theory, I think. Does someone have any idea?
=========>
=========>
alexandru_serghie1
New Contributor

I totally agree! Like was I with this post otherwise I was turning back and forth to the url-filtering feature.
pcraponi
Contributor II

short words... Action " PASS" on URL Filter release the URL but send the internal process to another proxies... Like App.Control, Antivirus and Fortiguard WebFiltering. If you put a URL as PASS on URL FILTER and block it on Fortiguard, the URL will be blocked. If you put a URL as EXEMPT on URL FILTER, they will bypass ALL others filters (including Fortiguard Web Filter). Read on documentation the difference between PASS and EXEMPT. regards, Paulo Raponi

Regards, Paulo Raponi

Regards, Paulo Raponi
mbrowndcm
New Contributor III

Paulo is totally correct. I use EXEMPT frequently. From a previous ticket of mine asking for an " order of operations document" : Web Filter order: Technical Note : FortiGate Web Filtering order - all FortiOS AV scan order: FortiGate Firewall Web Filtering , File filtering, and Antivirus engine sequence Email Order: You can get this info from FortiGate Admin Guide Hope this helps, Matt
" …you would also be running into the trap of looking for the answer to a question rather than a solution to a problem." - [link=http://blogs.msdn.com/b/oldnewthing/archive/2013/02/13/10393162.aspx]Raymond Chen[/link]
" …you would also be running into the trap of looking for the answer to a question rather than a solution to a problem." - [link=http://blogs.msdn.com/b/oldnewthing/archive/2013/02/13/10393162.aspx]Raymond Chen[/link]
Labels
Top Kudoed Authors