Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jnin
New Contributor

Allow Website Dont work

Hello guys I have a 100F and for some reason, the Web Filtering option is not allowing to view the "WhiteListed" sites.

 

I have block all categories but i allow just one website using Wildcard.

 

*github.com

 

but the Web Filter keeps blocking this website.

 

Any idea?

6 REPLIES 6
Toshi_Esumi
SuperUser
SuperUser

Do you happened to go by CoX_CX at Reddit? Slushmania answered to your question.

https://www.reddit.com/r/...ortinet_web_filtering/

jnin

No.. but reading the Reddit post he/she has the same problem that I have. Maybe is a global problem with Fortigate...... im worry about that this appliance are NOT cheap and i have 4 with the same "issue"

Yurisk

If your Allowed in static URL list website is blocked by Category it is in, then it will be blocked still, as Category block rating overrides static URL allow action. In such case you would also need to put this website into Custom Category with action Allow. 

In addition, if you are using gin the same security rule Web filtering and AppControl, AppControl most probably will be checked first (flow mode), and if it blocks the website URL filtering allow will not help either.

To be sure no further security checks block the website, change the action from Allow to Exempt.

 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
ranthony

This solved the issue for me, but I'm trying to get an idea of why it operates this way.  With firewall policies it will go down the list until it finds a match and stops.  The same with routing in the fortivoice system, it'll look for a matching rule and then stop.

 

But web filtering keeps going after a match.  Any idea what the thought process was behind making it that way?  (I realize it's a pedantic question but sometimes the "why" is important). 

mschoenberger

Is this a bug? If the Custom Category is set to Allow, and the URL is blocked in a regular category, the site is still blocked. If I set the Custom Category to Monitor, the web site is accessible.

 

I am on Version 6.2.4.

 

sw2090
Honored Contributor

ran into this too..accoarding to TAC this is wanted behaviour in FortiOS 6.2.x . 

The Fix/Workaroound they told be (and which made it work again) is to change the rule from "Allow" to "Monitor".

 

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Labels
Top Kudoed Authors