Helpful ReplyHot!Web Filter URL Not Working

Author
kelvinshee
New Member
  • Total Posts : 5
  • Scores: 0
  • Reward points: 0
  • Joined: 2016/06/09 19:31:28
  • Status: offline
2016/06/13 02:04:01 (permalink)
0

Web Filter URL Not Working

hi,
on FortiGate 60D, I want allow web filter from URL filter.
but I try for setting and is not working? is still blocking!
 
may know do have sample or how to solve it?
 
thanks.

Attached Image(s)

#1
kelvinshee
New Member
  • Total Posts : 5
  • Scores: 0
  • Reward points: 0
  • Joined: 2016/06/09 19:31:28
  • Status: offline
Re: Web Filter URL Not Working 2016/06/16 02:08:50 (permalink)
0
from the Fortigate category web filter is been block, is that i can allow fews website is allow from category? 
#2
kelvinshee
New Member
  • Total Posts : 5
  • Scores: 0
  • Reward points: 0
  • Joined: 2016/06/09 19:31:28
  • Status: offline
Re: Web Filter URL Not Working 2016/06/16 02:12:04 (permalink)
0
from the fortigate web filter category, i been set for block some category. 
but i want just allow fews website from that category. 
 
i been try for allow from URL filter. but is still blocking. 
how i can allow it? 
 
thanks.
#3
zhunissov4
Gold Member
  • Total Posts : 256
  • Scores: 25
  • Reward points: 0
  • Joined: 2015/10/12 04:00:01
  • Status: offline
Re: Web Filter URL Not Working 2016/06/16 03:09:42 (permalink) ☄ Helpfulby l.largo@ph.fujitsuc.om 2018/09/11 00:53:46
4.5 (2)
Hello,
 
You can solve this problem like this:
 
Enter to the Security Profiles->Web rating overrides, then create custom category, for example ALLOW_SITES. After that create New web rating overrides : enter the url of site which you want to allow , then select on Category custom category and on Sub - Category - ALLOW_SITES. Override all sites url to custom Sub-Category ALLOW -SITES which you want to allow.
 
Open Security Profiles - > Web Filter , delete your static url filtration , then on Fortiguard categories set Allow to ALLOW_SITES sub-category.
 
I hope it solves your problem!
Br, Aibek
 
 
 
#4
i2analytical
New Member
  • Total Posts : 6
  • Scores: 0
  • Reward points: 0
  • Joined: 2016/07/25 04:24:05
  • Status: offline
Re: Web Filter URL Not Working 2016/07/25 06:20:05 (permalink)
0
I got the same problem with page: http://www.sigmaaldrich.com/
can you help me  ?
I add exception and page still blocking images
#5
bcallan@phreedom.com
New Member
  • Total Posts : 4
  • Scores: 0
  • Reward points: 0
  • Joined: 2015/09/10 09:24:34
  • Status: offline
Re: Web Filter URL Not Working 2016/09/07 09:00:59 (permalink) ☄ Helpfulby Prab 2018/07/12 01:43:08
0
Did you resolve this?  I know it's a pretty stale thread, but maybe this will help you or the next person.
 
Static URL filter is slightly counter-intuitive and may not behave quite the way you expect.  Please review documentation (for 5.4, see http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-security-profiles-54/Web_Filter/Static%20URL%20Filter.htm).  Pay close attention to the notes for Allow action.  Allow passes the request on to other proxy functions, such as AV and Web Filter, so if the URL is in a blocked category, it will still be blocked.  The Exempt action bypasses other proxy functions, and while this does prevent web filter from being applied, it also prevents AV scanning.  A better solution may be to use web rating override to re-categorize a URL pattern from it's default Fortiguard category to another Fortiguard category or a custom category, then set that category action to the desired action.
#6
jimzky1026
New Member
  • Total Posts : 7
  • Scores: 0
  • Reward points: 0
  • Status: offline
Re: Web Filter URL Not Working 2019/09/30 05:46:52 (permalink)
0
I have the same problem. Some category in fortiguard are blocked but in static URL filter I put some websites to give an access but not working, still blocked... How to solved this?
post edited by jimzky1026 - 2019/09/30 05:51:18
#7
Dave Hall
Expert Member
  • Total Posts : 1548
  • Scores: 167
  • Reward points: 0
  • Joined: 2012/05/11 07:55:58
  • Location: Canada
  • Status: offline
Re: Web Filter URL Not Working 2019/09/30 06:47:33 (permalink)
0
Hi jimzky1026.
 
Need more information about your situation.  Where in the firewall rules chain is the FortiGuard web filtering policy applied to?  Do you have more than one firewall policy covering web traffic? Do you have a firewall policies covering general (any) traffic and if so is your web filtering policy placed above it?  Are you using security certificate inspection or pure SSL (deep packet) inspection?  Are the site(s) in question hosted an virtual cloud(hosted) servers - does an NSLookup resolve the hostname to more than one IP or FQDNs?
 
What firmware is your fgt running?

NSE4/FMG-VM64/FortiAnalyzer-VM/5.4/6.0 (FWF40C/FW92D/FGT200D/FGT101E)/ FAP220B/221C
#8
jimzky1026
New Member
  • Total Posts : 7
  • Scores: 0
  • Reward points: 0
  • Status: offline
Re: Web Filter URL Not Working 2019/09/30 08:28:50 (permalink)
0
I am using Fortigate 500E with fw version 5.4.0...here are the details what I did... I did this to make a test only.
1. I created a new web filter profile with enabled fortiguard and under general interest I blocked the sports category.
2. I enable static URL filter and add *.nba.com* and *.espn.com* wildcard - allow... to access only these 2 website under sports category...
3. In policy and objects I created new address (one PC that I am going to use for testing)
4. in policy and objects I created new ipv4 policy, incoming lan - outgoing wan - choose the source PC address - choose all in destination - choose all in service - choose the web filter profile I created and put the policy on top.
5. try to browse nba.com and espn.com but still blocked...
at first I don't use ssl deep inspection but in second trial I tried to use it but the website I allow still blocked. I downloaded the fortigate certificate and import to the PC that I am using for testing but still the same problem the website is blocked... what do you think is the problem?
Sorry for my english grammar I admit I am not good with that. :)
 
#9
Dave Hall
Expert Member
  • Total Posts : 1548
  • Scores: 167
  • Reward points: 0
  • Joined: 2012/05/11 07:55:58
  • Location: Canada
  • Status: offline
Re: Web Filter URL Not Working 2019/09/30 08:47:33 (permalink)
0
At 4 did you move this firewall policy up in the firewall rules chain?  Enable the byte or count column in the Policy section so you can see if the rule is getting hit.  Any general or similar firewall rule that is above this policy will likely get hit first and stop processing further firewall rules.

NSE4/FMG-VM64/FortiAnalyzer-VM/5.4/6.0 (FWF40C/FW92D/FGT200D/FGT101E)/ FAP220B/221C
#10
jimzky1026
New Member
  • Total Posts : 7
  • Scores: 0
  • Reward points: 0
  • Status: offline
Re: Web Filter URL Not Working 2019/09/30 09:00:26 (permalink)
0
yes actually i put this policy on top of all policies we have. It seems that the fortiguard is not recognizing the static URL filter setting. That is why I don't have a choice but to allow or monitor the sports category in our security profile
#11
Dave Hall
Expert Member
  • Total Posts : 1548
  • Scores: 167
  • Reward points: 0
  • Joined: 2012/05/11 07:55:58
  • Location: Canada
  • Status: offline
Re: Web Filter URL Not Working 2019/09/30 09:54:22 (permalink)
5 (1)
If you do not want the fgt to process any further UTM features, set the web filter action to exempt.
 

Note the point about bypassing FortiGuard web filter.  This was already pointed out by Bill in an earlier post of this thread.
post edited by Dave Hall - 2019/09/30 09:59:30

Attached Image(s)


NSE4/FMG-VM64/FortiAnalyzer-VM/5.4/6.0 (FWF40C/FW92D/FGT200D/FGT101E)/ FAP220B/221C
#12
muhkida
New Member
  • Total Posts : 18
  • Scores: 5
  • Reward points: 0
  • Status: offline
Re: Web Filter URL Not Working 2019/09/30 15:09:20 (permalink)
0
NEVER use the "allow" action. Our organization ALWAYS exempts URLs in the CLi with the following action:  "set exempt dlp fortiguard".
 
example:
 
edit 0
set url "yahoo.com"
set exempt dlp fortiguard
next
 
@kelvinshee - This also applies to the FortiGuard WCF categories. One should never set the action of an permitted/allowed Web Content Filter category to "Allow".  Any allowed categories should be set to "Monitor".  Otherwise, traffic to any domain allowed by category is not logged by the Fortigate.  Should a user become infected as a result of a site allowed by category, not logging the domain would make any post-mortem investigations extremely difficult.
#13
jimzky1026
New Member
  • Total Posts : 7
  • Scores: 0
  • Reward points: 0
  • Status: offline
Re: Web Filter URL Not Working 2019/09/30 22:31:54 (permalink)
0
I also tried to use exempt instead of allow but still the same nba.com and espn.com still blocked.
#14
jimzky1026
New Member
  • Total Posts : 7
  • Scores: 0
  • Reward points: 0
  • Status: offline
Re: Web Filter URL Not Working 2019/09/30 23:13:52 (permalink)
0
Yes! I think I find the solution after I do research I found the Web Rating Overrides. I do create new and add those websites which are blocked in fortiguard sports category and now nba.com and espn.com is working now. Thanks for your replies...
#15
Jump to:
© 2019 APG vNext Commercial Version 5.5