12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Web Filter<br />

Order of web filtering<br />

Web Filter<br />

The three main sections of the web filtering function, the Web Filter Content<br />

Block, the URL Filter, and the FortiGuard Web filter, interact with each other in<br />

such a way as to provide maximum control and protection for the Internet users.<br />

This section describes:<br />

• Order of web filtering<br />

• How web filtering works<br />

• Web filter controls<br />

• Content block<br />

• URL filter<br />

• FortiGuard - Web Filter<br />

Order of web filtering<br />

Web filters are applied in a specific order:<br />

1 URL Exempt (Web Exempt List)<br />

2 URL Block (Web URL Block)<br />

3 URL Block (Web Pattern Block)<br />

4 FortiGuard Web Filtering (Also called Category Block)<br />

5 Content Block (Web Content Block)<br />

6 Script Filter (Web Script Filter)<br />

7 Antivirus scanning<br />

The URL filter list is processed in order from top to bottom. (In FortiOS v2.80 the<br />

URL filter is processed as an unordered list.) An exempt match stops all further<br />

checking including AV scanning. An allow match exits the URL filter list and<br />

checks the other web filters.<br />

Local ratings are checked prior to other FortiGuard Web Filtering categories.<br />

The <strong>FortiGate</strong> unit applies the rules in this order and failure to <strong>com</strong>ply with a rule<br />

will automatically block a site despite what the setting for later filters might be.<br />

How web filtering works<br />

The following information shows how the filters interact with each other and how<br />

to use them to your advantage.<br />

The first section, the URL exempt and block filters, will allow you to decide what<br />

action to take for specific addresses. For example, if you want to exempt<br />

www.google.<strong>com</strong> from being scanned, you can add it to the URL exempt list. Then<br />

no web filtering or virus scanning will be taken to this web site.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 423

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!