Web filter
Category block
FortiGate-1000A/FA2 Administration Guide
01-28011-0254-20051115
337
Category block
You can filter http content by specific categories using the FortiGuard-Web Filtering
service.
This section describes:
•
FortiGuard-Web Filtering service
•
Category block configuration options
•
Category block reports
•
Category block reports options
•
Generating a category block report
•
Category block CLI configuration
FortiGuard-Web Filtering service
FortiGuard-Web Filtering is a managed web filtering solution provided by Fortinet.
FortiGuard-Web Filtering sorts hundreds of millions of web pages into a wide range of
categories that users can allow, block, or monitor. The FortiGate unit accesses the
nearest FortiGuard-Web Filtering Service Point to determine the category of a
requested web page and then follows the firewall policy configured for that user or
interface.
FortiGuard-Web Filtering categories and ratings
FortiGuard-Web Filtering includes over 60 million individual ratings of web sites
applying to hundreds of millions of pages. Pages are rated into 56 categories that
users can allow, block, or monitor. Categories may be added to or updated as the
Internet evolves. Users can also choose to allow, block, or monitor entire groups of
categories to make configuration simpler. Blocked pages are replaced with a
message indicating that the page is not accessible according to the Internet usage
policy.
FortiGuard-Web Filtering ratings are performed by a combination of proprietary
methods including text analysis, exploitation of the Web structure, and human raters.
Users can notify the FortiGuard-Web Filtering Service Points if they feel a web page is
not categorized correctly, and new sites are quickly rated as required.
See
“FortiGuard categories” on page 381
for a complete list and description of the
FortiGuard-Web Filtering web filter categories.
FortiGuard-Web Filtering Service Points
FortiGuard-Web Filtering Service Points provide worldwide coverage. By default, the
FortiGate unit communicates with the closest Service Point. If the Service Point
becomes unreachable for any reason, the FortiGate unit contacts another Service
Point and rating information is available within seconds. FortiGuard-Web Filtering
Service Points are highly scalable and new Service Points are added as required. The
FortiGate unit communicates with the Service Point over UDP on port 8888. You can
change the FortiGuard-Web Filtering hostname if required, using the CLI. See
“Category block CLI configuration” on page 340
.
Summary of Contents for FortiGate 1000A
Page 80: ...80 01 28011 0254 20051115 Fortinet Inc FortiGate IPv6 support System Network ...
Page 88: ...88 01 28011 0254 20051115 Fortinet Inc Dynamic IP System DHCP ...
Page 122: ...122 01 28011 0254 20051115 Fortinet Inc FortiManager System Config ...
Page 248: ...248 01 28011 0254 20051115 Fortinet Inc Protection profile Firewall ...
Page 260: ...260 01 28011 0254 20051115 Fortinet Inc CLI configuration User ...
Page 380: ...380 01 28011 0254 20051115 Fortinet Inc CLI configuration Log Report ...
Page 392: ...392 01 28011 0254 20051115 Fortinet Inc Glossary ...