Hi All,
I have a URL without domain name (using IP address) and it is matching to "unrated" category of the web filter. Since I want to allow the URL, I created a static URL filter and configured action to "exempt" while the policy is in flow mode. But still the URL was blocking from the unrated category and I could see it in the web filter logs. (with flow mode static URL filtering was not working at all)
Then I changed the policy to proxy mode. After that the URL was accessible but I could not see a log in the web filter logs but I cloud see a log entry in the forward log.
To ensure the operation, I removed the concerned URL from static URL filter, but surprisingly still I can access the URL.
Following security profiles are applied to the policy
AV
Web Filter
IPS
App control
SSL Cert inspection.
the URL : http://203.143.21.233/island/api/epaper
Thanks
SomeFWadmin
Flow mode scans the packets as they pass, without reassembly or thorough check, with the only possibility to reset the connection before it completes in case something is detected.
But that means some data is still passed to the client, so you may still see the page being displayed.
And this is valid for the IP site, because there is no DNS request to get the name and filter by that.
If you exempt an URL in Static URL filters, it should be exempt and not reach the category checking section.
When it is allowed, the log goes to forward traffic because it is allowed. Webfilter logs will only show Monitored/Blocked content.
Surprisingly still I can access the URL
>>> did you clear the existing session before you tried again?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1759 | |
1116 | |
766 | |
447 | |
242 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.