Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kelvinshee
New Contributor

Web Filter URL Not Working

hi,

on FortiGate 60D, I want allow web filter from URL filter.

but I try for setting and is not working? is still blocking!

 

may know do have sample or how to solve it?

 

thanks.

1 Solution
bcallan
New Contributor II

Did you resolve this?  I know it's a pretty stale thread, but maybe this will help you or the next person.

 

Static URL filter is slightly counter-intuitive and may not behave quite the way you expect.  Please review documentation (for 5.4, see http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-security-profiles-54/Web_Filter/Stati...).  Pay close attention to the notes for Allow action.  Allow passes the request on to other proxy functions, such as AV and Web Filter, so if the URL is in a blocked category, it will still be blocked.  The Exempt action bypasses other proxy functions, and while this does prevent web filter from being applied, it also prevents AV scanning.  A better solution may be to use web rating override to re-categorize a URL pattern from it's default Fortiguard category to another Fortiguard category or a custom category, then set that category action to the desired action.

View solution in original post

14 REPLIES 14
kelvinshee
New Contributor

from the Fortigate category web filter is been block, is that i can allow fews website is allow from category? 

kelvinshee
New Contributor

from the fortigate web filter category, i been set for block some category. 

but i want just allow fews website from that category. 

 

i been try for allow from URL filter. but is still blocking. 

how i can allow it? 

 

thanks.

bcallan
New Contributor II

Did you resolve this?  I know it's a pretty stale thread, but maybe this will help you or the next person.

 

Static URL filter is slightly counter-intuitive and may not behave quite the way you expect.  Please review documentation (for 5.4, see http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-security-profiles-54/Web_Filter/Stati...).  Pay close attention to the notes for Allow action.  Allow passes the request on to other proxy functions, such as AV and Web Filter, so if the URL is in a blocked category, it will still be blocked.  The Exempt action bypasses other proxy functions, and while this does prevent web filter from being applied, it also prevents AV scanning.  A better solution may be to use web rating override to re-categorize a URL pattern from it's default Fortiguard category to another Fortiguard category or a custom category, then set that category action to the desired action.

jimzky1026

I have the same problem. Some category in fortiguard are blocked but in static URL filter I put some websites to give an access but not working, still blocked... How to solved this?

Dave_Hall
Honored Contributor

Hi jimzky1026.

 

Need more information about your situation.  Where in the firewall rules chain is the FortiGuard web filtering policy applied to?  Do you have more than one firewall policy covering web traffic? Do you have a firewall policies covering general (any) traffic and if so is your web filtering policy placed above it?  Are you using security certificate inspection or pure SSL (deep packet) inspection?  Are the site(s) in question hosted an virtual cloud(hosted) servers - does an NSLookup resolve the hostname to more than one IP or FQDNs?

 

What firmware is your fgt running?

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
jimzky1026

I am using Fortigate 500E with fw version 5.4.0...here are the details what I did... I did this to make a test only.

1. I created a new web filter profile with enabled fortiguard and under general interest I blocked the sports category.

2. I enable static URL filter and add *.nba.com* and *.espn.com* wildcard - allow... to access only these 2 website under sports category...

3. In policy and objects I created new address (one PC that I am going to use for testing)

4. in policy and objects I created new ipv4 policy, incoming lan - outgoing wan - choose the source PC address - choose all in destination - choose all in service - choose the web filter profile I created and put the policy on top.

5. try to browse nba.com and espn.com but still blocked...

at first I don't use ssl deep inspection but in second trial I tried to use it but the website I allow still blocked. I downloaded the fortigate certificate and import to the PC that I am using for testing but still the same problem the website is blocked... what do you think is the problem?

Sorry for my english grammar I admit I am not good with that. :)

 

Dave_Hall
Honored Contributor

At 4 did you move this firewall policy up in the firewall rules chain?  Enable the byte or count column in the Policy section so you can see if the rule is getting hit.  Any general or similar firewall rule that is above this policy will likely get hit first and stop processing further firewall rules.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
jimzky1026

yes actually i put this policy on top of all policies we have. It seems that the fortiguard is not recognizing the static URL filter setting. That is why I don't have a choice but to allow or monitor the sports category in our security profile

Dave_Hall
Honored Contributor

If you do not want the fgt to process any further UTM features, set the web filter action to exempt.

 

Note the point about bypassing FortiGuard web filter.  This was already pointed out by Bill in an earlier post of this thread.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Labels
Top Kudoed Authors