Hi All,
we have fortigate 1000C V4 MR3 patch 12.
We want to block you tube earlier we were blocking in DNS level.
we tried these but no luck.
1>blocked in URL filter using wild card *.youtube.com(http is blocking but https is working )
2>Created the address with FQDN youtube.com and moved to deny Category on top policy.
3>enabled the https deep scan in protocol option.
4>tried to block using application controller.
5>profile enabled the https scanning all websites giving certificate error so disabled the scanning.
is there any options please suggest.
Are you able to upgrade to v5 to take advantage of certificate inspection (SNI)?
Please also be aware that FQDN address objects only cause the FortiGate to store 32 resolved IPs, so with a large domain like youtube.com, there is a high likelihood that the cached results will eventually not match the IP the client resolves to use, and the traffic will match another rule further down.
Regards, Chris McMullan Fortinet Ottawa
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1747 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.