FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
cborgato_FTNT
Article Id 194535

Description

This article describes how to block (deny) and notify specific traffic from the policy and eventually change or personalize the alert message.

set block-notification is the feature to use into the policy to notify about the block traffic.  This feature is disabled by default except in v5.2.2 where the default setting is enabled.


Solution

Create a deny policy and enable the block-notify feature.

# config firewall policy
    edit 293
        set srcintf "port1"
        set dstintf "port2"
        set srcaddr "all"
        set dstaddr "all"
        set schedule "always"
        set service "ALL"
        set logtraffic disable
        set send-deny-packet enable <-----
    next
end


Test the policy and check the alert-message on browser.

cborgato_FD36561_tn_FD36561-1.jpg

Personalize the relative block-notify message.

On the webgui go to System -> Config -> Replacement Messages.
Select the "Extended View" on the top right.
Look for "Block Notification Page" under 'Authentication'.

cborgato_FD36561_tn_FD36561-2.jpg

Modify the text message on the right-down text/html form and save using save button on the left.

cborgato_FD36561_tn_FD36561-3.jpg

It is possible to use html variable just typing %%.

For example, in this message %%POLICY%% return the policy ID. System will show all possible existing variables once typing %%[char]
cborgato_FD36561_tn_FD36561-4.jpg

 

Related Articles

Technical Tip: How to configure block-notification replacement messages for HTTP traffic

Technical Tip: Notification for blocked traffic default config 5.2.1 and 5.2.2 GA

 

Contributors