Hello,
Hope someone can help here.
The fortigate seems to skip web filtering following application control. Is this normal?
Thanks in advance.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi krusty,
I replied to the PM. Can you enable certificate-inspection under "SSL Inspection"? If you do not enable that, the IPS engine will not scan any SSL sessions.
HoMing
Hello krusty,
If you enabled a Web Filter profile with Application Control, and the App Control action does not drop the traffic, no, it should not skip web filtering. However, if App Control drops the traffic, then Web Filter will not apply. How did you test your policy? Can you send me your configuration file and let me know which policy ID are you using?
HoMing
Hello!
Application Control and IPs were applied before web filter, so this is a normal behaviour.
Hi,
I've PM'ed you the config.
Following application control we can still get to the blocked sites.
Thanks
Hi krusty,
I replied to the PM. Can you enable certificate-inspection under "SSL Inspection"? If you do not enable that, the IPS engine will not scan any SSL sessions.
HoMing
Are you using Proxy or flow mode?
Did you checked the following Settings?:
config firewall profile-protocol-options
config http
set Status enable # <- this must be enabled ; otherwise webfiltering AND AV won't work
end
next
end
Hi,
Thanks for the response.
It is in proxy-based mode.
config firewall profile-protocol-options is not enabled. Will this cause a loss of access on other policies if I enable it?
Cheers
Enabling certificate inspection worked.
Thanks for your help guys!! :)
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1641 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.