67-Web Filter Profile
67-Web Filter Profile
o Using the web filtering to block outbound communication to known malicious URLs.
o Reduction of the risk of infection from dangerous websites and protection of users.
o In FortiGate Firewall Web filtering classifies & controls web browsing based on content.
o Web filtering automatically prevents the attacks that leverage web as an attack vector.
o Including phishing links in emails, phishing sites, HTTP‐based command and control.
o Web Filtering prevents attacks includes malicious sites & pages that carry exploit kits.
o Web Filtering with enables safe web access, protecting users from dangerous websites.
o It restricts or controls user access to web resources & can be applied to firewall policies.
o FortiOS includes three preloaded web filter profiles default, monitor-all and wifi-default.
o Can customize these profiles, or you can create your own to manage network user access.
o The custom profile can be created based on your company’s internal security policies.
o The Web filtering should be customized to meet the unique needs of your organization.
o URL filter is called static URL filter by adding specific URLs with patterns containing text.
o URL Filter (static URL Filter) by adding specific URLs pattern containing Regular expressions.
o The FortiGate can allow, block, exempt & monitor web pages matching any specified URLs.
o The FortiGate Unit Firewall also, patterns, and can display a replacement message instead.
o Create URL filter using the GUI or CLI, after creating URL filter, attach it to web filter profile.
Usage Quota:
o Addition to using category and classification blocks and overrides to limit user access.
o User access to URLs, can set daily quota by category, category group, or classification.
o In FW usage Quotas allow access for a specified length of time or a specific bandwidth.
o It is calculated separately for each user and Quotas are reset every day at midnight.
o Usage Quotas can be set only for the actions of Monitor, Warning, or Authenticate.
o When the quota is reached, the traffic is blocked, and the replacement page displays.
o You can only use Usage quotas when FortiGate Unit Firewall inspection mode is Proxy.