Dear all,
i have a fortigate 100D version v5.2.2, i need to set a rules to block all streaming video but only allow youtube, i have done the web rating overrides youtube.com to custom group. but when i streaming video on youtube keep show video error.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
You may have better luck using an application sensor -- either create a new app sensor or preferably use your existing one that is covering web traffic; add an application filter that blocks all video/audio then create a second one that allows google video/media -- move this second app filter above the first one. Like firewall policy rules app filters are executed from top->down.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
You may have better luck using an application sensor -- either create a new app sensor or preferably use your existing one that is covering web traffic; add an application filter that blocks all video/audio then create a second one that allows google video/media -- move this second app filter above the first one. Like firewall policy rules app filters are executed from top->down.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Dave Hall wrote:You may have better luck using an application sensor -- either create a new app sensor or preferably use your existing one that is covering web traffic; add an application filter that blocks all video/audio then create a second one that allows google video/media -- move this second app filter above the first one. Like firewall policy rules app filters are executed from top->down.
[attachImg]https://forum.fortinet.com/download.axd?file=0;117879&where=message&f=allow-youtube only b.gif[/attachImg]
i have follow your way to do the filter,but some time fortigate unable detect facebook apps and block it, is just show ssl for facebook and allow, how to avoid this?
lokewing wrote:i have follow your way to do the filter,but some time fortigate unable detect facebook apps and block it, is just show ssl for facebook and allow, how to avoid this?[attachImg]https://forum.fortinet.com/download.axd?file=0;117982&where=message&f=Capture.JPG[/attachImg]
Facebook uses a wildcard security certificate, so if blocking it via FortiGuard categories (under social networking) or App sensor doesn't work you can try crafting a URL filter block (either using a wildcard *.facebook.com, or regex facebook.com). www.facebook.com resolves to star.c10r.facebook.com, so a URL filter block (one of the above) should work for that too, even under HTTPS.
Can you clarify (screen shot) of the app sensor used for blocking facebook? When you craft the app filter, only facebook should be selected under vendor with everything else set as all (default).
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Ok. This is not an issue at all. If you go to your logs and open security, webfilter log you will be able to see that it blocks all the traffic destined to googlevideo.com. You just have to add googlevideo.com to a static webfilter or do a override like you have done to youtube.com.
P.S. I prefer doing this via static web filter rather than overrides.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.