Hi,
I blocked the Social Networking category on the firewall but attempted to exempt one specific site, facebook.com, by adding it to the static URL filter with the action set to Exempt. While this allowed the main site to load, certain elements such as logos and images were still blocked.
Upon reviewing the logs, I discovered that Facebook relies on additional content delivery domains (e.g., static.xx.fbcdn.net) to fully render the site. Since these dependent URLs were not included in the exemption, they were automatically blocked by the firewall. After explicitly allowing these domains, the website loaded correctly and became fully functional.
The challenge is that the firewall’s static URL filter does not automatically recognize or exempt dependent domains when the primary domain is allowed. Each supporting domain must be manually identified and added to the exemption list. Is there any way we can do this so the firewall automatically recognize it and allow ?
hi,
usually this is how it works. you need to add/exempt each particular URI that the website has/needs to access to load different things.
you can try to exempt/allow in the webfilter a wildcard URL ( * ) with the Referrer facebook.com and/or www.facebook.com but you would need first to activate the option below for the field to be availabe in GUI:
config system setting
set gui-webfilter-advanced enable
end
@usmansa1 Hi, Unfortunately, this is how category URL working, I understand that sometimes it's bit hard to find out why and need to find out the URL that redirect the site/sub-domains etc to add into the exemption list however there is not possible FortiGate can find this automaticlly
| User | Count |
|---|---|
| 2836 | |
| 1433 | |
| 812 | |
| 793 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.