FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
abarushka
Staff
Staff
Article Id 196179

Description

 
This article explains the order in which web filtering steps are executed.


Solution

 
There is a specific order of execution of the web filtering steps:
 
  1. Static URL filtering (Note when using the URL filter ‘Exempt’ option, Antivirus, File Filter, and DLP scanning are exempt besides web-filtering by default. It is possible to configure manually any particular inspection(s) which are to be bypassed by using the 'set exempt' command in 'config webfilter urlfilter').

  2. FortiGuard categories.

  3. Content.

  4. Advanced options (i.e. Java applets (options available only when inspection mode is set to proxy)).

    abarushka_FD40476_tn_FD40476-1.jpg

Note:

FortiOS 6.2 has a File Filter added to the Webfilter profile. This functions correctly only when proxy-mode inspection is used (File filter).
FortiOS 6.4 has a File Filter as a separate Security Profile, with individual settings, including a limited flow-based operation mode.
 
Related document: