Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Mbutler522010
New Contributor

looking for best way to allow students access to just testing sites

I have a set of students that are denied access to the internet (via parental request form) and I have placed them in a AD group. I thought it would be easy, just not include the group in a policy that permits internet access through the firewall. However, I have a set of 30 or so sites that are required for all students to access - even if they are denied all else on internet - due to state testing requirements. is the best way to simply create a policy that all students can get to those sites and place it at the top of the policy list? it seems easy but I hate the idea of a student being allowed in one rule and denied in a different rule (the regular one that forbids students in the no-internet group) Would a better way be to create a local category and then a web-URL filter profile that denies all except that? or is there another way I have not even thought of? any ideas would be appreciated Mark
4 REPLIES 4
rwpatterson
Valued Contributor III

Welcome to the forums.
ORIGINAL: Mbutler522010 Would a better way be to create a local category and then a web-URL filter profile that denies all except that? any ideas would be appreciated Mark
That is the way I have Windows Updates configured as well as some other sites everyone needs to get to. It' s been working happily now for years. Actually, if there is no allow rule, then the traffic will be denied. No reason to create a stand alone ' deny' rule.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Mbutler522010
New Contributor

thanks Bob! Seems like such a basic thing...lol
Osama_Shatnawi
New Contributor

you can create a local category that includes all the allowed websites and use one policy to control the internet traffic for all users
I have a set of students that are denied access to the internet (via parental request form) and I have placed them in a AD group. I thought it would be easy, just not include the group in a policy that permits internet access through the firewall. However, I have a set of 30 or so sites that are required for all students to access - even if they are denied all else on internet - due to state testing requirements. is the best way to simply create a policy that all students can get to those sites and place it at the top of the policy list? it seems easy but I hate the idea of a student being allowed in one rule and denied in a different rule (the regular one that forbids students in the no-internet group) Would a better way be to create a local category and then a web-URL filter profile that denies all except that? or is there another way I have not even thought of?

Osama

Osama
Nihas
New Contributor

Definitely local category will help you if the count of website is less. But you have to make sure the application control also has to be controlled , like they can use a proxy VPN client , torrents etc. ( I know those are class room machines, but the new guys are more talented than anyone .. )
Nihas [\b]
Nihas [\b]
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors