Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Manuel93
New Contributor

URL FILTER

I have a web filter that blocks streaming media and download on the fortiguard catergory based filter. However, I have permitted access to youtube under the url filter using both allow and exempt actions yet it doesn't work-(fortinet still blocks access to this). How can this be fixed? It appears that despite there been a hit for the static url filter the firewall still proceeds to send the traffic to the fortiguard category based filter for inspection which would obviously block the traffic

4 REPLIES 4
srajeswaran
Staff
Staff

Are you using deep-inspection or certificate-inspection ? If you are using certificate inspection, it could be due to the SNI mis-match, can you try disabling ""block-invalid-hostname" option in webfilter profile" and test?

ref: https://community.fortinet.com/t5/FortiGate/HTTPS-Webfiltering-without-deep-scan-enabled-details/ta-...

Regards,

Suraj

- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

sw2090
Honored Contributor

Sounds like your blocking rule is not "exempt" but "allow" or "monitor". 

Also keep in mind that url filter rules are matched top=>down like policies.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
akushwaha
Staff
Staff

Hi,
As I understand you it is being blocked because it is matching allow rule in web filter, please configure only exempt option to permit YouTube traffic. Please refer to this below article regarding static URL filter:
Technical Tip: Using a static URL filter feature t... - Fortinet Community


Regards,

Abhimanyu

abarushka
Staff
Staff

Hello,

 

Allowing youtube.com URL may not be sufficient, since googlevideo.com URL is used to load videos.

FortiGate
Labels
Top Kudoed Authors