[using FortiGate 100D v5.02] I setup the WebFilter to block some
categories, like Social Networking. If a user tries to access using HTTP
it works fine, blocking the access. But if the user tries using HTTPS,
the access is allowed. I read about the n...
Tomorrow, we'll upgrade our 100D from 5.0.13 to 5.2.10 and after to
5.4.4.We'd a lot of VIPs, +100 policies, 11 FortiAPs, IPsec VPN, SSL
VPN, Policies Routes, AD SSO... So, let's cross the fingers
It' s not a good idea block using Firewall Address. First because some
providers, like Google, use the same IP for more than one service. So
you will block " youtube.com" and this can block " docs.google.com"
too... Second because most of these servi...
I found out a more elegant solution! 1. Create in Firewall Objects ->
Address a FQDN record for every site that you have to block 2.
[optional] Create a Group that will include all the above records 3.
Create a rule in Policy->Policy that will deny t...
I also can block HTTPS pages using SSL Inspection and WebFilter, but I
got the same certificate errors. My company have more than 120
computers. I think it will not be easy to import Fortinet_CA_SSLProxy
for all computers ...
I' m already using FortiGuard DNS. I found this documentation, but I' m
not sure if is it what you said.
http://docs.fortinet.com/fos50hlp/50/index.html#page/FortiOS%205.0%20Handbook/UTM.005.12.html
Best regards.
You are leaving our website
You are leaving our site and we cannot be held responsible for the content of external websites