Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tuan2tech
New Contributor II

Why are there so many icloud domains in the Proxy Avoidance category?

Hi everyone

 

Why are there so many icloud domains in the Proxy Avoidance category?

 

Proxy Category.jpg

2 REPLIES 2
spoojary
Staff
Staff

The Fortinet FortiGate categorizes various domains based on their functionalities and the type of content they serve. Domains associated with iCloud services are categorized under "Proxy Avoidance" mainly because of the functionality iCloud offers.

Here are a few reasons:

  1. iCloud Drive: iCloud Drive can be used to store any data, and once the data is uploaded to iCloud, it can be accessed from anywhere, potentially bypassing corporate or school content filters and restrictions.

  2. iCloud Web Apps: With web-based versions of Pages, Numbers, Keynote, etc., users can upload, edit, and download content, again potentially bypassing restrictions.

  3. Shared Albums and iCloud Photos: These allow for content sharing and can also be accessed via web browsers.

  4. iCloud.com: It provides web-based access to multiple Apple services including Mail, Contacts, Calendar, Photos, iCloud Drive, and more.

  5. VPN-Like Functionality: Certain features, like iCloud Private Relay (introduced in iOS 15), function similarly to a VPN by encrypting a user's web traffic and routing it through two separate internet relays, making it difficult for outsiders to intercept or view.

Due to these functionalities, in a controlled environment like a corporate network, school, or a public institution, it's a concern that users might utilize these services to bypass network restrictions, share unauthorized content, or access restricted content. As a result, they are categorized under "Proxy Avoidance" to give network administrators an option to restrict or monitor the usage of these services.

If this categorization causes an issue or if certain essential services are getting blocked, network administrators can customize the web filter profiles in their FortiGate units to allow specific domains or URLs as needed.

Siddhanth Poojary
tuan2tech
New Contributor II

Hi you 

I added it to the web filler but it still shows up in the log

 

 

 

1-Proxy Category.jpg

 

Log-2.jpg

Labels
Top Kudoed Authors