Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Suneelkumar
New Contributor

Youtube not Bloking

Hi All,

 

we have fortigate 1000C V4 MR3 patch 12.

 

We want to block you tube earlier we were blocking in DNS level.

 

we tried these but no luck.

1>blocked in URL filter using wild card *.youtube.com(http is blocking but https is working )

2>Created the address with FQDN youtube.com and moved to deny Category on top policy.

3>enabled the https deep scan in protocol option.

4>tried to block using application controller.

5>profile enabled the https scanning all websites giving certificate error so disabled the scanning.

 

is there any options please suggest.

2 REPLIES 2
Bromont_FTNT
Staff
Staff

Are you able to upgrade to v5 to take advantage of certificate inspection (SNI)?

Christopher_McMullan

Please also be aware that FQDN address objects only cause the FortiGate to store 32 resolved IPs, so with a large domain like youtube.com, there is a high likelihood that the cached results will eventually not match the IP the client resolves to use, and the traffic will match another rule further down.

Regards, Chris McMullan Fortinet Ottawa

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors