Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
someFWadmin
New Contributor

Web Filter working strangely

Hi All, 

 

I have a URL without domain name (using IP address) and it is matching to "unrated" category of the web filter. Since I want to allow the URL, I created a static URL filter and configured action to "exempt" while the policy is in flow mode. But still the URL was blocking from the unrated category and I could see it in the web filter logs. (with flow mode static URL filtering was not working at all)

 

Then I changed the policy to proxy mode. After that the URL was accessible but I could not see a log in the web filter logs but I cloud see a log entry in the forward log.

To ensure the operation, I removed the concerned URL from static URL filter, but surprisingly still I can access the URL.

 

Following security profiles are applied to the policy

AV

Web Filter

IPS

App control

SSL Cert inspection.

 

the URL :  http://203.143.21.233/island/api/epaper

 

Thanks

SomeFWadmin

1 REPLY 1
AlexC-FTNT
Staff
Staff

Flow mode scans the packets as they pass, without reassembly or thorough check, with the only possibility to reset the connection before it completes in case something is detected.
But that means some data is still passed to the client, so you may still see the page being displayed.
And this is valid for the IP site, because there is no DNS request to get the name and filter by that.

If you exempt an URL in Static URL filters, it should be exempt and not reach the category checking section.
When it is allowed, the log goes to forward traffic because it is allowed. Webfilter logs will only show Monitored/Blocked content.

Surprisingly still I can access the URL
>>> did you clear the existing session before you tried again?


- Toss a 'Like' to your fixxer, oh Valley of Plenty! and chose the solution, too00oo -
Labels
Top Kudoed Authors