Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

https bypass

Ok, folks have figured out how to bypass my blocked url list by using https Now, how do I stop it, and these other tricks they are using? http://hubpages.com/hub/Bypass-Unblock-Or-Disable-Fortiguard-Web-Filtering-Firewall-Fortinet-School-Web-Filter Thanks, RushB
5 REPLIES 5
billp
Contributor

There are a number of tactics to thwart attempts like this. 1. Use OpenDNS and restrict access to adult, proxy sites. It adds another level of protection/annoyance. Just make sure you block calls to other DNS services on port 53. 2. You can install a custom cert and then scan HTTPS sites, but this requires a some extra work, uses firewall resources, and you have to push out custom certs to all users. 3. Make sure " HTTPS" is selected on the Enable Fortiguard Web Filtering area in the Protection Profile. This will block the site if the URL in the SSL certificate matches the blocked domain. 4. Enable IPS filtering to monitor or block appropriate apps. You should be able to block the leading proxy software such as Ultrasurf, although this is always a game of cat and mouse. Hope that helps to get started.

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
ejhardin
Contributor

1. Double check your web filter settings,even without deep ssl scanning you can block https urls. Also enable strict blocking and other advanced options in the web filter profile. You should probably enable safe search for goole, bing, and yahoo. 2. You can use a cloud dns services to help but I would not recommend it as it has been proven to be the main cause for slow internet downloads. We used opendns for a year and now that we have removed it our downloads are (no joke) 10x faster. (http://apcmag.com/why-using-google-dns-opendns-is-a-bad-idea.htm) 3. Enable application control. This will help a lot with proxies sites and proxy software. If they are using a usb application or try to install a proxy software the application control policy will stop it. It will also work for web browsers and other websites/programs other than proxies hulu, netflix, your tube, etc... 4. If you can enable Deep SSL scanning. 5. Another option would be to create two vdoms, enable Explicit Web Proxy in vdom 1 and deny as much traffic as you can and create a web proxy rule. Enable all clients browsers to use the proxy with authentication and then in vdom two create a rule from the web proxy to the internet and apply all profile policies (firewall, av, web filter, application control, DLP, Deep SSL scanning)
ejhardin
Contributor

6. If you can install the forticlient and monitor/block all programs installed on the laptop or pc. On the fortinet under Endpoint - NAC profile. 7. Side note enable authentication for outbound internet traffic. You can create different profiles for each groups. Management could have a relaxed policy and everyone else a strict policy.
Not applicable

Was speaking with the Engineer that has been helping me with this issue, and the problem is that with youtube the certificate name is *.google.com - how can I block youtube access through https without killing google? Thanks, RushB
billp
Contributor

RushB, Don' t you just love Google? You can block Youtube using Application Control. The video itself is not sent via SSL. Users will still be able to get onto the Youtube site itself and search, but would not be able to actually play any videos. I just tried it. Hopefully that will do what you want.

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors