Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Understanding Web Filtering !!!
Hi forum,
I ' m trying to use Web filtering feature include URL Filtering and Fortiguard Categories.
First, I BLOCK all New and Media category in working hours, It work well.
Then I ALLOW only some news webs in URL Filter list, but It does not work as I expected. Those websites still blocked by Fortiguard category.
I check the Fortigate document and see the web filtering order:
1.URL filter
2.FortiGuard Web filter
3......
4....
5.Antivirus Scan
I ' m sure that I do not enable strict blocking.
My fortigate use OS 5.0 GA patch1. Can anyone tell me whether I lack some config to achieve my goal?
=========>
=========>
5 REPLIES 5
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you create a custom category and joined the url to custom category from the UTM Security Profiles -> Web filter -> Rating Overrides menu ?
The custom category has to be set as allowed in your web filtering profile.
I hope this helps you.
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes! Thanks to your reply.
I used Rating Overrides settings, and it works well.
But I do not understand the process order of web filtering.
I read this sentence in Fortigate document " Any attempt to access a URL that matches a URL pattern with an allow action is permitted. The traffic is passed to the remaining antivirus proxy operations, including FortiGuard Web Filter, web content filter, web script filters, and antivirus scanning."
First I allow that specific URL in URL Filter list, then I block that URL' s category by Fortiguard Category. Then the URL is blocked by Fortiguard Category.
It does not go as the theory, I think.
Does someone have any idea?
=========>
=========>
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I totally agree! Like was I with this post otherwise I was turning back and forth to the url-filtering feature.
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
short words...
Action " PASS" on URL Filter release the URL but send the internal process to another proxies... Like App.Control, Antivirus and Fortiguard WebFiltering.
If you put a URL as PASS on URL FILTER and block it on Fortiguard, the URL will be blocked.
If you put a URL as EXEMPT on URL FILTER, they will bypass ALL others filters (including Fortiguard Web Filter).
Read on documentation the difference between PASS and EXEMPT.
regards,
Paulo Raponi
Regards, Paulo Raponi
Regards, Paulo Raponi
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Paulo is totally correct. I use EXEMPT frequently.
From a previous ticket of mine asking for an " order of operations document" :
Web Filter order:
Technical Note : FortiGate Web Filtering order - all FortiOS
AV scan order:
FortiGate Firewall Web Filtering , File filtering, and Antivirus engine sequence
Email Order:
You can get this info from FortiGate Admin Guide
Hope this helps,
Matt
" …you would also be running into the trap of looking for the answer to a question rather than a solution to a problem." - [link=http://blogs.msdn.com/b/oldnewthing/archive/2013/02/13/10393162.aspx]Raymond Chen[/link]
" …you would also be running into the trap of looking for the answer
to a question rather than a solution to a problem." -
[link=http://blogs.msdn.com/b/oldnewthing/archive/2013/02/13/10393162.aspx]Raymond
Chen[/link]
