We have our FGT-600Es. I have a question which I cant find the answer to. Currently we are using another device for web filtering which is offering us free cloud based web filtering too (at the flick of a switch).
I want to explore ditching that service and using the built in Fortigate Web Filtering. Setup for local users is fine, however we have several users who will be offsite with company owned devices. Some of these users will not be using VPN to connect in so;
1 - I want to check if FGT offer a cloud based web filtering setup without the need to connect back to the main unit for rule checks etc, so that users can use their own internet connection to browse to the website (if the site is not blocked) and not use the office bandwidth. Is there anyway to do this?
2 - If this is not an option, is there a an agent/client that can be installed to force them to check the FGT Web filtering and again if allowed, use their own internet connection to browse to the page? Or do they have to have the VPN on?
To expand on fortinet_tn's response, FortiClient would be your best bet most likely in terms of cost and efficiency. FortiClient has a local Application FW and Web Filter which can have the same policy as your FortiGate. So if clients are off-net they are still protected and monitored even without connecting to VPN.
You can also use FortiClient to keep VPN auto-connected and always on and force all traffic through your FortiGate.
Or you can use SASE which uses Fortinet's cloud-based services to enforce client policy.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.