Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
7bits
New Contributor

Publishing OWA with URL Filtering

Hi there I' ve a question. Is it possible with a fortinet 60c to make URL Filtering like ISA Server 2006 or TMG2010 to make only available: /owa /ActiveSync.... etc.?? If yes do i have to go under URL Filtering and add it like that -> https://exchangeserver/owa | https://exchangeserver/ActiveSync ??? Thanks for an advice! Greetings 7bits
5 REPLIES 5
ejhardin
Contributor

Not possible with a fortigate... This is way I still have my ISA server.
lmuir
New Contributor

ORIGINAL: ejhardin Not possible with a fortigate... This is way I still have my ISA server.
Wait, why not? Couldn' t you SSL offload to the FGT, and use URL filtering?
ejhardin
Contributor

Wait, why not? Couldn' t you SSL offload to the FGT, and use URL filtering?
Maybe... I don' t have a device that will do VIP SSL Offloading. 7bits stated that he has a 60c and I don' t believe that the 60c has the ability to VIP SSL Offload.
ekontos

Has anyone been able to resolve this issue or do we have to look at a different firewall product?

sw2090
Honored Contributor

to be able to do url filtering with https you have to have ssl deep inspection enabled on the policy.

Then make one policy that hits trtaffic to the server and set an urlfilter that only allows those two paths.

Maybe it is a good idea to create those as wildcard rules. Set the action to exempt instead of allow.

Then create a third rule that blocks everything. This one must be the last rule.

 

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Labels
Top Kudoed Authors