Hello everyone
I hope you can support me: I added a page in the web filter menu, in the static url filter-enable url filter section, only that people can still see the web page, what should I do so that they do not really have access to that site? The appliance that I have is a Fortigate 60D.
Thank you very much for your support
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
You just need to apply "default" Web Filter profile, which you just modified, to the outgoing FW policy.
You just need to apply "default" Web Filter profile, which you just modified, to the outgoing FW policy.
Everything worked correctly. I appreciate your support very much
To prevent access to a specific website using the Fortigate 60D appliance and its web filter feature, you can follow these steps:
After these steps, when users try to access the specified website, they should receive a block page indicating that the site is not accessible.
Keep in mind that for the web filter to work correctly, you need to ensure that the Fortigate 60D is properly configured with the necessary network and security policies, and that traffic is passing through the appliance as intended.
It's also worth noting that web filtering can be bypassed by various means, such as using VPNs or proxy servers. Therefore, it's important to regularly review and update your web filter rules to adapt to new websites or methods that may be used to bypass restrictions.
for more information check this: yardgearsguide.com
I'd be happy to help you with your Fortigate 60D configuration! If you've added a page to the web filter menu but people can still access it, there may be some misconfiguration or additional steps required. Here are some troubleshooting steps to ensure that the web page is blocked correctly:
Double-check the Web Filter Profile: Ensure that the web filter profile you created is applied to the correct security policy that controls the traffic. If the profile is not correctly associated with the security policy, the filtering rules won't take effect.
Verify the URL Filter List: In the web filter profile, check the "Static URL Filter" section to make sure the page's URL is correctly added to the blocked list. Verify that the URL you added matches the one you want to block and that there are no typos or errors in the URL.
Confirm Policy Order: Make sure the policy that applies the web filter profile is evaluated before any policies that allow access. Fortigate policies are evaluated from top to bottom, and the first matching policy will be applied. If there's a policy allowing access to the website like https://10thclassresult.site/ above the filtering policy, it will take precedence.
Test from Different IP: Sometimes, the Fortigate firewall may have cached DNS results. To ensure the filtering is working correctly, try accessing the website from a different device or IP address that hasn't accessed the site before.
Clear DNS Cache: If the Fortigate device is responsible for DNS resolution, you may need to clear the DNS cache to ensure it recognizes the updated filtering rules.
Here's a step-by-step guide to help you resolve the issue:
Double-check the URL filter configuration: a. Log in to your Fortigate 60D appliance. b. Navigate to the web filter menu and select "Static URL Filter" or "URL Filter" (depending on your firmware version). c. Make sure you have correctly added the URL or domain name of the webpage you want to block.
Verify the policy order: a. Check the security policy order to ensure the web filter policy is placed above any other policies that might allow access to the webpage. b. Fortigate evaluates policies from top to bottom, and the first matching policy is applied. If a less restrictive policy (e.g., a general allow policy) is matched before the URL filter policy, it could still allow access to the blocked webpage.
Check the policy action: a. Ensure that the action associated with the web filter policy is set to "Deny" or "Block." b. If the action is set to "Warning" or "Monitor," users might receive a warning or the webpage access will be logged, but they can still access the website .
Verify user groups and IPs: a. Ensure that the web filter policy is correctly applied to the relevant user groups or IP addresses. b. If the policy is not targeting the correct users or devices, it won't block the webpage for those users.
Refresh the web filter: a. After making any changes to the policies or configurations, refresh or apply the changes in the Fortigate management interface.
Clear the DNS cache on client devices: a. Sometimes, client devices store DNS cache, which may temporarily allow access to websites even after blocking. Clear the DNS cache on the client devices or wait for the cache to expire.
Test from a different network: a. To ensure the blocking is not specific to the network, test accessing the webpage from a different network or device.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1517 | |
1013 | |
749 | |
443 | |
209 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.