Hi,
On my Fortigate 600C, I have defined rules that block pornographic sites.
But I see that it is possible to display pornographic images with Google images. My question is : how to block pornographic images with google images ?
Thanks for your help.
Regards
Ferdo
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Turn on safe search on for search engines in web filter.
Still doubt whether this can be thoroughly blocked.
To add, enable deep inspection in the profile as well as turn on the "Rate Images by URL" in the webfilter profile.
jintrah wrote:To add, enable deep inspection in the profile as well as turn on the "Rate Images by URL" in the webfilter profile.
wouldn't just certificate inspection achieve this?
Deep inspection slows down things i guess, also depends on the FGT model and no. of users right?
allwynmasc wrote:wouldn't just certificate inspection achieve this?
No, Certificate Inspection only looks up the SNI [usually the domain you are visiting.] information of the website when the website is first visited. If the domain is allowed, it goes through and all future sessions will pass without any furhter ssl inspection.
Deep packet inspection [DPI], on the other hand makes the fortigate to act as the man in the middle. Allowing fortigate to inspect all contents inside the secure packet.
With Certificate Inspection:
You visit google.com, once the domain is allowed, the fortigate doesn't know what search queries are you typing as it is communicated over https since we are NOT doing DPI
and it cannot modify the URL as it cannot see the part past the hostname.
With Deep Inspection:
Fortigate acts as a man in the middle and can see the contents being transferred but more importantly it can see the URL, allowing the fortigate to intercept and add the safe=active parameter to force safe search everytime.
This also allows a network admin to monitor what search queries are being entered.
allwynmasc wrote:Most models support it, but yes no of users and model in combination will decide performance
Deep inspection slows down things i guess, also depends on the FGT model and no. of users right?
try enabling Safe Search in Web Filter profile that you have applied in the policy.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1696 | |
1091 | |
752 | |
446 | |
228 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.