12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring a protection profile<br />

Firewall Protection Profile<br />

Web resume download<br />

block<br />

Block Invalid URLs<br />

See “Web Filter” on page 423 for more web filter configuration options.<br />

FortiGuard Web Filtering options<br />

Enable to block downloading parts of a file that have already<br />

been partially downloaded. Enabling this option will prevent the<br />

unintentional download of virus files hidden in fragmented files.<br />

Note that some types of files, such as PDFs, are fragmented to<br />

increase download speed. Enabling this option can cause<br />

download interruptions with these types of file.<br />

The <strong>FortiGate</strong> unit can perform validation on the CN to ensure<br />

that it is a valid hostname before applying web-filtering. If the<br />

CN is not a valid hostname, the traffic will be blocked if you<br />

enable this option.<br />

Figure 215:Protection profile FortiGuard Web Filtering options<br />

The following options are available for web category filtering through the<br />

protection profile.<br />

Enable FortiGuard Web<br />

Filtering<br />

Enable FortiGuard Web<br />

Filtering Overrides<br />

Provide details for<br />

blocked HTTP 4xx and<br />

5xx errors (HTTP only)<br />

Enable FortiGuard Web Filtering category blocking.<br />

Enable category overrides. When selected, a list of groups is<br />

displayed. If no groups are available, the option is grayed out.<br />

For more information about overrides, see “Viewing the<br />

override list” on page 436 and “Configuring override rules” on<br />

page 437. For more information about groups, see “User<br />

groups” on page 386.<br />

Display a replacement message for 400 and 500-series HTTP<br />

errors. If the error is allowed through, malicious or objectionable<br />

sites can use these <strong>com</strong>mon error pages to circumvent web<br />

category blocking.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

334 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!