FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ntaneja
Staff
Staff
Article Id 196345

Description

 

This article explains how to block access to some Google accounts and services while allowing access to accounts in the domains in the exception list.

 

Note:
The device should be in 'Proxy-based' Inspection mode.

SSL (Deep) Inspection is Mandatory.

Solution

 

To enable this feature in the GUI:

 

On FortiOS 5.6 & 6.0:

 

  1. Go to Security Profiles -> Web Filter.
    Go to the Proxy Options section.

 
FortiOS 6.2.x and above:
  1. Enable 'Restrict Google account usage to specific domains'.

 
  1. Select the + button and enter the domains that Google can access, for example, www.fortinet.com.
     

     
    When Google services like Gmail are used, only traffic from the domain of www.fortinet.com can go through. Traffic from other domains is blocked.
     
    If the web-based mail category is blocked in the web filter profile, it is necessary to add mail.google.com in the web filter rating override with the category that is in the monitored state in the web filter profile.