12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Web filter controls<br />

Web Filter<br />

If you have blocked a pattern but want certain users to have access to URLs<br />

within that pattern, you can use the Override within the FortiGuard Web Filter. This<br />

will allow you to specify which users have access to which blocked URLs and how<br />

long they have that access. For example, you want User1 to be able to access<br />

www.fakeLAND.<strong>com</strong> for 1 hour. You can use this section to set up the exemption.<br />

Any user listed in an override must fill out an online authentication form before the<br />

FortiGuard unit will grant access to the blocked URL.<br />

FortiGuard Web Filter also lets you create local categories to block groups of<br />

URLs. Once you have created the category, you can use the local rating to add<br />

specific sites to the local category you have created. You then use the Firewall ><br />

Protection Profile to tell the FortiGuard Unit what action to take with the Local<br />

category. The local ratings overwrite the FortiGuard ratings.<br />

Finally the FortiGuard unit applies script filtering for ActiveX, Cookie, and Java<br />

applet, which can be configured in Firewall > Protection Profile > Web Filtering.<br />

Once you have finished configuring all of these settings, you still have to turn them<br />

all on in the Firewall > Protection Profile > Web filtering and Firewall ><br />

Protection Profile >FortiGuard Web Filtering. By enabling them here, you are<br />

telling the <strong>FortiGate</strong> unit to start using the filters as you have configured them.<br />

This section describes how to configure web filtering options. Web filtering<br />

functions must be enabled in the active protection profile for the corresponding<br />

settings in this section to have any effect.<br />

Web filter controls<br />

As a general rule you go to Web Filter to configure the web filtering settings and to<br />

enable the filters for use in a protection profile. To actually activate the enabled<br />

filters you go to Firewall> Protection Profile.<br />

Note: Enabled means that the filter will be used when you turn on web filtering. It does not<br />

mean that the filter is turned on. To turn on all enabled filters you must go to Firewall><br />

Protection Profile.<br />

FortiGuard - Web Filter is described in detail in“FortiGuard Web Filtering options”<br />

on page 334. Rating corrections as well as suggesting ratings for new pages can<br />

be submitted on the FortiGuard Center web page. Visit the Fortinet Knowledge<br />

Center for details and a link to the FortiGuard Center.<br />

The following tables <strong>com</strong>pare web filtering options in protection profiles and the<br />

web filter menu.<br />

Table 37: Web filter and Protection Profile web content block configuration<br />

Protection Profile web filtering options<br />

Web Content Block<br />

Enable or disable web page blocking based<br />

on the banned words and patterns in the<br />

content block list for HTTP traffic.<br />

Web Filter setting<br />

Web Filter > Content Block<br />

Add words and patterns to block web<br />

pages containing those words or<br />

patterns.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

424 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!