Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ralphian08
New Contributor

allow specific user from LAN to access the facebook.

Hi All

 

I am new with fortigate 100D ver 5.0 firewall.

I need your help how to allow specific users from LAN to access facebook?.

step by step procedure would be really helpful.

 

1 Solution
gschmitt
Valued Contributor

Go to System > Config > Features and make sure Application Control and Multiple Security Profiles is enabled.

Security Profiles > Application Control select your default profile, configure as needed.

Unter Application Overrides select Add Signatures, search for "Facebook" select all and Use Selected Signatures

Set Action to Block and Apply

In the upper right corner select Clone and name the profile default-allowFailbook

Set action to Allow/Monitor and Apply

To to User & Devices > User > User Groups and create two groups

Go to User & Devices > User > User Definition, create users and put them in the two groups

Go to Policy & Objects > Policy > IPv4 and select Create New

Create two policies from your internal interface to your internet facing interface select Source User(s) and under Security Profiles your two Application Control profiles respectively

Move the policy allowing Facebook on top of the other just to make sure

View solution in original post

3 REPLIES 3
gschmitt
Valued Contributor

Go to System > Config > Features and make sure Application Control and Multiple Security Profiles is enabled.

Security Profiles > Application Control select your default profile, configure as needed.

Unter Application Overrides select Add Signatures, search for "Facebook" select all and Use Selected Signatures

Set Action to Block and Apply

In the upper right corner select Clone and name the profile default-allowFailbook

Set action to Allow/Monitor and Apply

To to User & Devices > User > User Groups and create two groups

Go to User & Devices > User > User Definition, create users and put them in the two groups

Go to Policy & Objects > Policy > IPv4 and select Create New

Create two policies from your internal interface to your internet facing interface select Source User(s) and under Security Profiles your two Application Control profiles respectively

Move the policy allowing Facebook on top of the other just to make sure

ralphian08
New Contributor

Thanks for reply gschmitt i will try this later.

ralphian08

Hi gschmitt

 

Sorry for the very Late Reply.

Your instruction works..

Thank You for your help and much appreciated. 

 

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors