Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Myathu
New Contributor

Web filter not working

I have fortinet 30E, I upgraded firmware 6.2, now I blocked social media but it's working... Why this happens???
6 REPLIES 6
isamt
Contributor

Is it https:\\ links that still work?

You have to enable SSL/SSH inspection in the Internet browsing policy and choose at least certificate-inspection or use your own cert.

Myathu
New Contributor

All are done but not woking

i Put flow based is it ok know..

 

 

isamt

If still not working, paste copy of the rule and other relevant config.

Also confirm whether filter not working for http/https sites or just https sites.

Myathu
New Contributor

 I found the issue..... My policy order is the problem.

i have 5 policy's,  each has web filter applied eg: 1 is fb & Youtube blocked another one is fb only blocked. etc..

may i know how to order my policies pls help me................

isamt

The Fortigate rule base operates top down.

Hence, you should place your most restrictive policies at the top of the list.

Once a policy is matched in the list any policies lower in the list are not checked.

 

Example

 

#         source                        destination                     service      Interface

1          All                              all                                 http,https   Wan1

2          sales_users                 all                                 http,https   Wan1  

 

If you have a web filter set on rule 2 to block Facebook, users will still be able to access Facebook as they will hit

rule 1 first which allows all http, https traffic.

 

In this case to block Facebook you would move rule 2 above rule 1

 

#         source                        destination                     service      Interface

2          sales_users                 all                                 http,https   Wan1  

1          All                              all                                 http,https   Wan1

 

That way sales_users cannot access Facebook, but any user not in the sales_users group can

 

Hope that helps

Myathu
New Contributor

Thanks for the help

Labels
Top Kudoed Authors