Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

best way to block all sites or allow certain sites only

I know I can create URL list with " com" , " net" , " org" , etc entries and block sites that way, but there must be more straightforward solution. Similarly, what if I want to have a list of say 10 sites only to be assigned to a specfici protection profile and everything else will get blocked? Thank you in advance, P
3 REPLIES 3
rwpatterson
Valued Contributor III

If you use the Fortiguard Web Filtering service, create a custom Local Category (Web Filter > Fortigaurd Web Filter > Local Categories > Create New). Give it a logical name. Next click on the Local ratings tab. hit ' Create New' , add the web site to be added (do this once for each site). Use as little info as possible here to cover more URLs. For example to include ebay, add ' ebay.com' . This will cover www.ebay.com, ebay.com/cgi. . .., and everything else. If you enter ' www.ebay.com' , ebay.com won' t work. Now before you' re done, you have to expand out the ' Local Categories' bullet, and click the check box for the local category you wish to add this entry to. When you' ve added all the sites this policy is allowed to see, add it to the correct protection profile, and you' re done. (In the protection profile, it' s under ' Fortiguard Web Filtering > Category > Local Categorties' ) This is exactly how I allow all entities to get to ' Windows Update' even if not allowed Internet access.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

Too easy... thanks for the tip. How do you go about blocking all the other sites? (great example about allowing Windows Updates only) Cheers P
rwpatterson
Valued Contributor III

In the Fortiguard Web Filtering, block everything but your custom category. Install that in the protection profile, select allow, and everything will be blocked by Fortiguard, except your handful of sites.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors