FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Vedaant
Staff
Staff
Article Id 276489
Description This article describes how to authenticate users/user group for block category using web rating override. It can be configured as flow or proxy-based
Scope FortiGate.
Solution

Create a web-filter profile, and block the category in the FortiGuard category-based filter.

Go to Security Profiles -> Web Filter and select Create New.

web filter test new.PNG

 

Create another web-filter category for users to override the blocked category using another web-filter profile.

 

web filter 2 new.PNG

 

web-filters.PNG

 

To use a user/user group to override the blocked category, allow users to override blocked categories and add another web filter profile.

 

1.PNG

 

Create a web rating override. It is possible to check categories and sub-categories using the Look up rating. The overrides in Custom Category point to another web-filter profile that has been created (web-filter 2).

 

2.PNG

 

Add user/ user-group to 'authenticate' in the custom category. 

 

authenticate.PNG

 

adding usergrp in custom profile.PNG

 

To use the web filter profile in a security policy in the GUI:

  1. Go to Policy & Objects -> Security Policy and click Create New.

  2. Enter a name for the policy, and configure the remaining settings as required.

Under Security Profiles, enable Web Filter and select the web filter.

firewall policy.PNG

 

Now when a user in the user group tries to access a website which comes under the block category, it will override the user group using web-rating override. The user needs to authenticate using their credentials.

 

10-web filter override.PNG

 

 

override authenticate.PNG

 

After authenticating, the user will be able to access the blocked website.

 

Contributors