Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Baboda
New Contributor

wildcard FQDN policy

Hello,

with FortiOS 5.2.9 is see wildcard FQDN address is not supported. What I need to do is create a policy which deny all except (for example) *.google.com. I could create a webfilter profile with a static wildcard url filter and then assign it to the ipv4 policy maybe ? but how can I deny all the other traffic ?

 

 

Thanks

5 REPLIES 5
hklb
Contributor II

Hi

 

With URL filter :

- *.google.com  :exempt 

- * : deny 

 

Lucas

Baboda
New Contributor

Thanks Lucas,

that is also what I was thinking to do with a url filter deny * in web filter profile (other then exempted ones). Another question is if exempting google or lets suppose any other site, even malicious ones, does it means that those sites are totally exempted even though for example included in a not allowed category in the same web filter profile ?

hmtay_FTNT

Hello Baboda,

 

>>Another question is if exempting google or lets suppose any other site, even malicious ones, does it means that those sites are totally exempted even though for example included in a not allowed category in the same web filter profile ?

 

Yes, it will be exempted from the FortiGuard categories too.

 

HoMing

Baboda
New Contributor

Thanks a lot, just the last question is what in url filter the "monitor" action difference to "exempt" or "allow" ones.

Baboda
New Contributor

Perfect! thanks a lot :)

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors