Web Filter
For Windows, macOS, and Linux profiles, you must enable FortiProxy (Disable Only When Troubleshooting) on the System Settings tab to use the Web Filter options.
Configuration |
Description |
|
---|---|---|
Web Filter |
Enable web filtering. Enable or disable the eye icon to show or hide this feature from the end user in FortiClient. |
|
General |
||
Client Web Filtering When On-Net |
Enable client web filtering when on-net. Only available for Windows and macOS profiles. This setting affects the Block Access to Malicious Websites setting in Malware Protection. |
|
Log All URLs |
Log all URLs. When this setting is disabled, FortiClient EMS only logs URLs as specified by per-category or per-URL settings. |
|
Log User Initiated Traffic |
Log only user-initiated traffic. |
|
Action On HTTPS Site Blocking |
|
|
Enable Web Browser Plugin for HTTPS Web Filtering |
Enable a web browser plugin for HTTPS web filtering. This improves detection and enforcement of Web Filter rules on HTTPS sites. After this option is enabled, the user must open the browser to approve installing the new plugin. The web browser plugin is installed only for the Google Chrome browser on Windows platforms. |
|
|
Sync Mode |
When this option is enabled, the web browser waits for a response from an HTTPS request before sending another HTTPS request. |
|
Check User Initiated Traffic Only |
Use the web browser plugin for only user-initiated traffic. This allows for faster processing. When this option is disabled, the plugin checks all URL requests. |
Enable Safe Search |
When Safe Search is enabled, the endpoint's Google search is set to Restricted mode. For Windows and macOS profiles, enabling Safe Search also sets YouTube access to Strict Restricted access. To set YouTube access to Moderate Restricted or Unrestricted YouTube access, you can disable Safe Search and configure Google Search and YouTube access with the Google Admin Console instead of FortiClient EMS. For Chromebook profiles, you can configure the Restriction Level to Strict or Moderate for YouTube access. This setting only affects YouTube access. Your Chromebook extension must be version 1.0.1.0023 or later for this feature. |
|
Site Categories |
Enable site categories from FortiGuard. When you disable site categories, the exclusion list protects FortiClient. See the FortiGuard website for descriptions of the available categories and subcategories. For all categories below, you can configure an action for the entire site category by selecting one of the following:
You can also click the + button beside the site category to view all subcategories and configure individual actions (Block, Warn, Allow, Monitor) for each subcategory. Each site category's subcategories are listed below. |
|
Adult/Mature Content |
|
|
Bandwidth Consuming |
|
|
General Interest-Business |
|
|
General Interest-Personal |
|
|
Potentially Liable |
|
|
Security Risk |
|
|
Unrated |
|
|
Rate IP Addresses |
Have FortiClient request the rating of the site by URL and IP address separately, providing additional security against attempts to bypass the FortiGuard Web Filter. If the rating determined by the domain name and the rating determined by the IP address differ, a weighting assigned to the different categories determines the action that FortiClient enforces. The higher weighted category will take precedence in determining the action. This will have the side effect that sometimes the Action is determined by the classification based on the domain name and other times it is determined by the classification that is based on the IP address. FortiGuard Web Filter ratings for IP addresses are not updated as quickly as ratings for URLs. This can sometimes cause FortiClient to allow access to sites that should be blocked, or to block sites that should be allowed. An example of how this would work would be if a URL's rating based on the domain name indicated that it belonged in the category Lingerie and Swimsuit, which is allowed but the category assigned to the IP address was Pornography which has an action of Block, because the Pornography category has a higher weight the effective action is Block. |
|
Use HTTPS Rating Server |
By default, Web Filter sends URL rating requests to the FortiGuard rating server via UDP protocol. You can instead enable Web Filter to send the requests via TCP protocol. |
|
Allow websites when rating error occurs |
Configure the action to take with all websites when FortiGuard is temporarily unavailable. This may occur when an endpoint is forced to access a network via a captive portal. FortiClient takes the configured action until contact is reestablished with FortiGuard. Available options are:
|
|
FortiGuard Server Location |
Configure the FortiGuard server location. If FortiGuard Anycast is selected for the Server field, you can select from global, U.S., or Europe. If FortiGuard is selected for the Server field, you can select from global or U.S. When Global is selected, FortiClient uses the closest FortiGuard server. FortiClient connects to FortiGuard to query for URL ratings. The URLs connected to for each server location are as follows:
|
|
Server |
Configure the FortiGuard server to FortiGuard or FortiGuard Anycast. |
|
Exclusion List |
||
Action |
Select one of the following actions:
|
|
URL |
Enter specific URLs to allow, block, or monitor. You can provide the full URL or only the domain name. |
|
Referrer/Host |
Enter a specific referrer or host to allow, block, or monitor. You can provide the full URL or only the domain name. If the end user visits the URL through the referrer provided, EMS considers the rule a match and applies the specified action. If the end user visits the URL directly or through a different referrer, EMS does not consider the rule a match and does not apply the specified action. |
|
Type |
Select one of the following types:
You can use wildcard characters and Perl Compatible Regular Expressions (PCRE). This field only applies to the value in the URL field and does not apply to the value in the Referrer/Host field. |
|
Move this rule up/Move this rule down |
Move the exclusion rule up/down in the list. If multiple exclusion rules are applicable, EMS applies the first applicable exclusion rule. |