Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
DP_TCMT
New Contributor

Web filtering for cloud/remote users

Hi All

We have our FGT-600Es.  I have a question which I cant find the answer to.  Currently we are using another device for web filtering which is offering us free cloud based web filtering too (at the flick of a switch). 

 

I want to explore ditching that service and using the built in Fortigate Web Filtering.  Setup for local users is fine, however we have several users who will be offsite with company owned devices.  Some of these users will not be using VPN to connect in so;

 

1 - I want to check if FGT offer a cloud based web filtering setup without the need to connect back to the main unit for rule checks etc, so that users can use their own internet connection to browse to the website (if the site is not blocked) and not use the office bandwidth. Is there anyway to do this? 

 

2 - If this is not an option, is there a an agent/client that can be installed to force them to check the FGT Web filtering and again if allowed, use their own internet connection to browse to the page? Or do they have to have the VPN on?

 

Hopefully that makes sense to everyone!

Thanks

1 Solution
fortinet_tn
Staff
Staff

You might want to look into FortiClient EMS or FortiSASE depending on you needs and direction. 

View solution in original post

3 REPLIES 3
fortinet_tn
Staff
Staff

You might want to look into FortiClient EMS or FortiSASE depending on you needs and direction. 

gfleming
Staff
Staff

To expand on fortinet_tn's response, FortiClient would be your best bet most likely in terms of cost and efficiency. FortiClient has a local Application FW and Web Filter which can have the same policy as your FortiGate. So if clients are off-net they are still protected and monitored even without connecting to VPN.

 

You can also use FortiClient to keep VPN auto-connected and always on and force all traffic through your FortiGate.

 

Or you can use SASE which uses Fortinet's cloud-based services to enforce client policy.

Cheers,
Graham
DP_TCMT
New Contributor

Hi both,

 

Thanks for the advice.  Will try and get hold of my Fortinet local reps and see if they can throw some pricing towards us.

 

Cheers,

Dave

Labels
Top Kudoed Authors