12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Firewall Protection Profile<br />

Configuring a protection profile<br />

Rate images by URL<br />

(blocked images will be<br />

replaced with blanks)<br />

(HTTP only)<br />

Allow websites when a<br />

rating error occurs<br />

Strict Blocking<br />

Rate URLs by domain<br />

and IP address<br />

Category<br />

Classification<br />

Block images that have been rated by FortiGuard. Blocked<br />

images are replaced on the originating web pages with blanks.<br />

Image types that are rated are GIF, JPEG, PNG, BMP, and<br />

TIFF.<br />

Allow web pages that return a rating error from the web filtering<br />

service.<br />

Strict blocking only has an effect when either a URL fits into a<br />

category and classification or IP rating is enabled. With IP<br />

rating enabled, all URLs have two categories and up to two<br />

classifications (one set for the domain and one set for the IP<br />

address). All URLs belong to at least one category (Unrated is<br />

a category) and may belong to one classification too.<br />

If strict blocking is enabled, a site is blocked if it is in at least<br />

one blocked category or classification and only allowed if all<br />

categories or classifications it falls under are allowed.<br />

With strict blocking disabled, a site is allowed if it belongs to at<br />

least one allowed category or classification and only blocked if<br />

all categories or classifications it falls under are allowed.<br />

For example, if a protection profile blocks “Search Engines” but<br />

allows “Image Search” and the URL “images.google.ca” falls<br />

into the Search Engines category and the Image Search<br />

classification.<br />

With strict blocking enabled, this URL is blocked because it<br />

belongs to the Search Engines category, which is blocked.<br />

With strict blocking disabled, the URL is allowed because it is<br />

classified as Image Search, which is allowed. It would only be<br />

blocked if both the Search Engines category and Image Search<br />

classification were blocked.<br />

This option is enabled by default.<br />

When enabled, this option sends both the URL and the IP<br />

address of the requested site for checking, providing additional<br />

security against attempts to bypass the FortiGuard system.<br />

However, because IP rating is not updated as quickly as URL<br />

rating, some false ratings may occur.<br />

This option is disabled by default.<br />

The FortiGuard Web Filtering content filtering service provides<br />

many categories by which to filter web traffic. Set the action to<br />

take on web pages for each category. Choose from allow,<br />

block, log, or allow override.<br />

Classifications block whole classes of web sites. Web sites that<br />

provide cached content, Google for example, can be blocked.<br />

Web sites that allow image, audio, or video searches can also<br />

be blocked. Web sites that are classified are also rated in one<br />

of the categories or are unrated. Choose from allow, block,<br />

monitor, or allow override.<br />

See “FortiGuard - Web Filter” on page 435 for more category blocking<br />

configuration options.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 335

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!