Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
JerryPWhite1
New Contributor II

Not really sure where to start.

I have gone through the initial setup of my new 800C. Can't seem to understand the way this device uses security policies. For starters, I want to use a web filter to block all websites to the default user profile. The options inside the web filter are proxy, flow-based, and dns. I have read that proxy based is the most secure. Do I need to setup an explicit proxy for this to work? I have so many other questions but support tells me they won't help unless there is a problem.

Jerry Paul White

Network Engineer/Tech Supervisor

" 01001000 01100001 01110110 01100101 00100000 01100001 00100000 01000111 01101111 01101111 01100100 00100000 01000100 01100001 01111001"

Jerry Paul White Network Engineer/Tech Supervisor " 01001000 01100001 01110110 01100101 00100000 01100001 00100000 01000111 01101111 01101111 01100100 00100000 01000100 01100001 01111001"
6 REPLIES 6
Bromont_FTNT
Staff
Staff

 

You don't need explicit proxy for proxy based filters. How are you identifying your users for the filters? LDAP/AD? IP?

JerryPWhite1
New Contributor II

Right now it's just by ip address for testing. Once I put it into production I will want to join it to the domain.

Jerry Paul White

Network Engineer/Tech Supervisor

" 01001000 01100001 01110110 01100101 00100000 01100001 00100000 01000111 01101111 01101111 01100100 00100000 01000100 01100001 01111001"

Jerry Paul White Network Engineer/Tech Supervisor " 01001000 01100001 01110110 01100101 00100000 01100001 00100000 01000111 01101111 01101111 01100100 00100000 01000100 01100001 01111001"
JerryPWhite1

Any help would be greatly appreciated.

Jerry Paul White

Network Engineer/Tech Supervisor

" 01001000 01100001 01110110 01100101 00100000 01100001 00100000 01000111 01101111 01101111 01100100 00100000 01000100 01100001 01111001"

Jerry Paul White Network Engineer/Tech Supervisor " 01001000 01100001 01110110 01100101 00100000 01100001 00100000 01000111 01101111 01101111 01100100 00100000 01000100 01100001 01111001"
KM_FTNT
Staff
Staff

Fortinet has a video guides site where they post goo technical video showing how to setup various features.  They have few on setting up Web Filtering security profile, here is the latest one: http://video.fortinet.com/video/115/basic-web-filtering-5-2

 

I suggest you go to video.fortinet.com and have a look at few videos to understand how it all works.

 

hope this helps.

 

Technical Video - video.fortinet.com

Technical Docs - docs.fortinet.com

 

Dave_Hall
Honored Contributor

@jpwhite

 

See this post.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
JerryPWhite1
New Contributor II

Part of my issue was the latest update 5.2.2. I created a ticket and an engineer had me downgrade to 5.2.1. This resolved my issue. To begin with my issue was that I could not apply a web filter in proxy mode. It would not work at all.

Jerry Paul White

Network Engineer/Tech Supervisor

" 01001000 01100001 01110110 01100101 00100000 01100001 00100000 01000111 01101111 01101111 01100100 00100000 01000100 01100001 01111001"

Jerry Paul White Network Engineer/Tech Supervisor " 01001000 01100001 01110110 01100101 00100000 01100001 00100000 01000111 01101111 01101111 01100100 00100000 01000100 01100001 01111001"
Labels
Top Kudoed Authors