Have a Fortigate setup with Deep SSL inspection with web filtering, the web filtering works if i go to https://websitegoes here.
However, if i type in the IP of that site it goes straight through, is that to be expected? how can i change this?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I'm not sure how effective it will be in your case but you can try: 'Rate URLs by domain and IP Address'. You can find it in the 'Web Filter' security profile, in the 'Rating Options' section.
Keep in mind when rating URLs by IP address is some site may be hosted on "cloud" servers and/or may be classified as such or pulls page elements (e.g. images) from other domains, so you may run into rating issues.
Your best bet if you really want to nix users from browsing by IP address is to perhaps craft a URL using perl or regular expression that triggers on a IP-like addresses - I never tried this myself so do not know how effective it would be.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Yes correct, virtual-hosting could become an issue. You should block by dns or content in the URL string.
Ken Felix
PCNSE
NSE
StrongSwan
emnoc wrote:Hi Ken,Yes correct, virtual-hosting could become an issue. You should block by dns or content in the URL string.
Ken Felix
DNS blocking works but the ip of the website doesnt, is my only hope to block all ip based requests via regex?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.