Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Nark0t
New Contributor

Schedule for Social media sites

Hi,

 

I don't know i this is possible, but I am trying to setup a schedule that blocks only facebook and social media traffic at certain times for specific users, but allows all other services during those times. for example:

 

users have access to allowed internet services but are only allowed to access facebook between 8:00-9:00am in the mornings and 12:00-13:00 in the afternoons. I have setup schedules and schedule groups and we use FortiSSO for user authentication however I cant seem to get it working as when I enable the schedule it blocks all internet access except for those times.

 

Thanks in advance :) 

1 Solution
hubertzw

So, the policy order is:

1) FB_Access with specific group (for those who can access FB in specific time) - action permit

2) Block-FB with specific group (not sure what is the policy name) - action block

3) Internet - action permit

 

With FSSO it should work

View solution in original post

5 REPLIES 5
hubertzw
Contributor III

do you have 2 firewall policies? one should be with time control for the FB and the second for the Internet with permit without time control

Nark0t
New Contributor

Hi I do have 2 policies, however realized I should provide better over view of my policies:  

 

I have groups for Full access, limited access and no access with users assigned to each group and allowed services are always open on those groups.

 

Now I want to take specific users that are in the Limited access group and only allow Facebook access at specific times but not affect other internet services.

What I have done is created a Limit_FB group on my AD and added them as member of the group as well as keep them on the limited access group.

I have created a FB_Access policy and setup a schedule for that policy. I have taken the same web filtering and app control profiles as the limited access group and just blocked social media in those profiles and placed the policy above the limited access policy.

this should technically work correct?

 

Hope this makes sense

hubertzw

So, the policy order is:

1) FB_Access with specific group (for those who can access FB in specific time) - action permit

2) Block-FB with specific group (not sure what is the policy name) - action block

3) Internet - action permit

 

With FSSO it should work

TawannaVidovich

I totally agree with you

hardep457
New Contributor

this will work. i am agree with you

Labels
Top Kudoed Authors