Laboratorio 8
Laboratorio 8
Web Filtering
To configure FortiGate for web filtering based on FortiGuard categories, you must make
sure that FortiGate has a valid FortiGuard security subscription license. The license
provides the web filtering capabilities necessary to protect against inappropriate websites.
Then, you must configure a category-based web filter security profile on FortiGate, and
apply the security profile in a firewall policy to inspect the HTTP traffic.
Finally, you can test different actions that FortiGate has taken, according to the website
rating.
2. On the Dashboard, locate the Licenses widget, and then hover over Web Filter to
confirm that the service is licensed and active.
7. Click OK.
www.facebook.com
This is one of the websites you will use later to test your web filter.
3. Use the Web Filter Lookup tool again to find the web filter category for the
following websites:
www.skype.com
www.ask.com
www.bing.com
You will test your web filter using these websites also.
The following table shows the category assigned to each URL, as well as the action you will
configure FortiGate to take based on your web filter security profile:
Category Action
Local Disable
Categories
Adult/Mature Block
Content
Bandwidth Allow
Consuming
Unrated Block
You will also enable the logs to store and analyze the security events that the web traffic
generates.
3. In the Security Profiles section, enable Web Filter, and then select default.
4. Hover over the warning sign that appears beside the SSL Inspection field.
6. Under Log Allowed Traffic, make sure that Security Events is selected.
A warning appears, according to the predefined action for this website category.
4. Open a new browser tab, and then go to www.skype.com.
A warning appears, according to the predefined action for this website category.
5. Click Proceed to accept the warning and access the website.
This website appears because it belongs to the Search Engines and Portals category,
which is set to Allow.
Field Value
URL www.bing.com
3. Click OK.
The website is blocked, and it matches a local rating instead of a FortiGuard rating.
Stop and think!
The Edit Filter window opens, which allows you to modify the warning interval and select
the user groups.
Field Value
5. Click OK.
6. Click OK.
To create a user
1. Continuing on the Local-FortiGate GUI, click User & Authentication > User
Definition.
Username student
Password fortinet
5. Click Next.
6. Click Next.
8. Click Submit.
A warning appears. Notice that it is a different message from the one that appeared before.
2. Click Proceed.
Username student
Password fortinet
4. Click Continue.
Field Value
URL www.bing.com
Type Simple
Action Block
Field Value
Status Enable
6. Click OK.
7. Click OK.
4. Click OK.
8. Click OK.
A warning appears. Notice that it is a different message from the one that appeared before.
Initially,
the www.bing.com website has
the category Search Engines
and Portals, which was set
to Allow and does not generate
a security log.