Web Filter Profile FortiGuard Filter Lab:
Go to Policy & Objects > Object Configurations >Security Profiles>Web Filter there are
preloaded four predefined web filters.
1 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 00966564303717
FortiGuard Filter:
To block category, go to Policy & Objects > Object Configurations >Security Profiles>Web Filter
and go to the FortiGuard category based filter section.
Action Description
Allow Permit access to the sites in the category.
Block Prevent access to the sites in the category. Users trying to access a blocked
site sees a replacement message indicating the site is blocked.
Monitor Permits and logs access to sites in the category.
Warning Displays a message to the user allowing them to continue if they choose.
Authenticate Requires the user to authenticate with the FortiGate before allowing access.
2 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 00966564303717
Open the Bandwidth Consuming- section by clicking the + icon beside it. Select Streaming
Media and Download and then select Block.
Continue on the FortiManager GUI, click Policy Packages, Click HQ-FW>Firewall Policy. Select
the first policy at the top of the list, and then click Edit. Click the Security Profiles check box.
Configure AntiVirus Profile and SSL/SSH Inspection and click OK.
3 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 00966564303717
Install the Policy:
Continue on the FortiManager GUI, click Install>Install Wizard.
Select Install Policy Package & Device Settings. Conform that the HQ-FW policy package is
selected. And then click Next.
Confirm that the HQ-FW device is selected, and then click Next.
4 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 00966564303717
Click Install Preview to see changes that will be applied to FortiGate. Click Close on the Install
Preview page. Click Install.
Once done click Finish.
5 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 00966564303717
Verification & Testing:
Validate the URL filter results by going to a blocked website. Go to the YouTube website, you
see the replacement message.
To check web filter logs in the GUI, Go to Log & Report > Web Filter.
6 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 00966564303717
Warning Message:
To configure a warning, go to Policy & Objects > Object Configurations >Security Profiles>Web
Filter and go to the FortiGuard category based filter section. Open the General Interest -
Business section by clicking the + icon beside it. Select Web Hosting and then select Warning.
Set the Warning Interval which is the interval when the warning page appears again after the
user chooses to continue.
7 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 00966564303717
To validate that configured the warning, Go to a website belonging to the selected category, for
example, www.godaddy.com & see warning page where you can choose to Proceed or Go Back.
Authenticate Message:
To configure an authentication, go to Policy & Objects > Object Configurations >Security
Profiles>Web Filter and go to the FortiGuard category based filter section. Open the General
Interest - Business section by clicking the + icon beside it. Select Web Hosting and then select
Authenticate.
8 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 00966564303717
Set the Warning Interval which is the interval when the authentication page appears again after
authentication. Click the + icon beside Selected User Group and select a user group. You must
have a valid user group to use this feature.
To validate that configured the warning, Go to a website belonging to the selected category, for
example, www.godaddy.com & see warning page where you can choose to Proceed or Go Back.
9 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 00966564303717
Click Proceed to check that the authentication page appears. Enter the username and password
of the user group you selected and click Continue. If the credentials are correct, the traffic is
allowed through.
10 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 00966564303717