FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
jskrivan_FTNT
Article Id 197571
Description

This KB article describes, which information is included within a webfilter request, sent from a FortiGate unit to the FortiGuard service, in order to evaluate the website category.

The information sent includes the following:

  • FortiGate unit serial number,
  • FortiGate unit IP address,
  • Website full URL, including scheme, hostname and path.

As per OWASP guidelines, security sensitive information should never be included as a part of the URL, as URLs are often logged on intermediate proxies and firewalls. It is up to the application vendor or owner, to ensure that URLs do not leak any sensitive information.

Note that these FortiGuard requests are also obfuscated, and can not be easily read using a packet capture tool.

 


Contributors