Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Anne
New Contributor III

Block youtube and FB

Hi All, I used Application Control to block access to FB and YT. It worked fine but here are the results: Tested on Chrome. www.facebook.com = No Data Recieved https://facebook.com = SSL connection error www.youtube.com = App currently unreachable Firefox: www.facebook.com = Connection was reset https://facebook.com = Connection interrupted www.youtube.com = Connection was reset All tests experiences were like long page loading delays with an eventual failure. The error messages are a bit strange also - I would have expected a firewall blocking error?? Is there a way these messages can be changed. Thanks Anne
8 REPLIES 8
AtiT
Valued Contributor

Hi Anne, Maybe I' m wrong but the application control will not inform the user whether something has been blocked or not. It will just block it. How the browser will interpret the blocked traffic it can be different. I think better is to use the Webfilter (URL filter) for blocking. Application control to use block only some parts for example Facebook.Chat etc...

AtiT

AtiT
billp
Contributor

That' s correct. Application blocking will not give an error. It will just stop the session from completing. If you use FortiOS 5.0.x, there is something called a Fortinet Top Bar available in Proxy Options. It will overlay a small window over your browser to let you know that an application was blocked. It also gives login information and other status messages. I haven' t used this feature, so I don' t know how reliable it is. It might be worth investigating. Blocking the domain in the web filter will also give you a proper error message. However, domain blocking is not as reliable as application blocking. It' s not reliable for blocking the HTTPS versions of websites if you don' t have SSL deep-packet inspection enabled. This is especially true for Google-based sites that use a similar *.google.com SSL certificate for almost all their websites. For Facebook, I found it was more reliable to block via Application Control. I don' t block Youtube, so not sure how well App Control works for that. It might be easier to create a School ID for Youtube and force all Youtube traffic to educational videos. That effectively ruins it as an entertainment source.

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
Bromont_FTNT
Staff
Staff

Also even if using webfilter with certificate/SNI to block HTTPS sites you' ll still get browser warnings as currently the blocked page uses the Fortigate certificate
Aliasgar
New Contributor

Hello all, i am facing same issue, after applying SSL inspection ON, i already import Root authorities certificate to IE, downloaded from Fortigate, still when i open any HTTPS web site gives me error, Please assist me. Thank you ASJ
Bromont_FTNT

If using Firefox the certificate needs to be imported into Firefox as well.
Dipen
New Contributor III

Application Control is more reliable method to block but as said by other participants Application Control dosent give any Block Page like Web Filter. Blocking of HTTPS websites has been a looong issue with Fortigate...Not enabled till HTTPS Deep Packet inspection is enabled. Even after putting all Certificates etc in place the Deep Packet inspection renders many Web pages lifeless.

Ahead of the Threat. FCNSA v5 / FCNSP v5

Fortigate 1000C / 1000D / 1500D

 

Ahead of the Threat. FCNSA v5 / FCNSP v5 Fortigate 1000C / 1000D / 1500D
TuncayBAS
Contributor II

Please Read: http://support.fortinet.com/forum/tm.asp?m=105004&p=1&mpage=2&tmode=1&smode=1&key=&language=#

Tuncay BAS RZK Muhendislik Turkey NSE 4 5 6 FCESP v5

Tuncay BAS RZK Muhendislik Turkey NSE 4 5 6 FCESP v5
shah_nawaj
New Contributor

Hi,

 

Good day!!!

 

I want to keep running Facebook in my network, but i block the video over Facebook, is there any way to do it.

 

Thanks & Regards,

Shah

Labels
Top Kudoed Authors