Fortinet black logo

CLI Reference

config webfilter profile

config webfilter profile

Configure Web filter profiles.

config webfilter profile
    Description: Configure Web filter profiles.
    edit <name>
        set comment {var-string}
        set extended-log [enable|disable]
        config file-filter
            Description: File filter.
            set status [enable|disable]
            set log [enable|disable]
            set scan-archive-contents [enable|disable]
            config entries
                Description: File filter entries.
                edit <filter>
                    set comment {var-string}
                    set protocol {option1}, {option2}, ...
                    set action [log|block]
                    set direction [incoming|outgoing|...]
                    set password-protected [yes|any]
                    set file-type <name1>, <name2>, ...
                next
            end
        end
        config ftgd-wf
            Description: FortiGuard Web Filter settings.
            set options {option1}, {option2}, ...
            set exempt-quota {user}
            set ovrd {user}
            config filters
                Description: FortiGuard filters.
                edit <id>
                    set category {integer}
                    set action [block|authenticate|...]
                    set warn-duration {user}
                    set auth-usr-grp <name1>, <name2>, ...
                    set log [enable|disable]
                    set override-replacemsg {string}
                    set warning-prompt [per-domain|per-category]
                    set warning-duration-type [session|timeout]
                next
            end
            config quota
                Description: FortiGuard traffic quota settings.
                edit <id>
                    set category {user}
                    set type [time|traffic]
                    set unit [B|KB|...]
                    set value {integer}
                    set duration {user}
                    set override-replacemsg {string}
                next
            end
            set max-quota-timeout {integer}
            set rate-image-urls [disable|enable]
            set rate-javascript-urls [disable|enable]
            set rate-css-urls [disable|enable]
            set rate-crl-urls [disable|enable]
        end
        set https-replacemsg [enable|disable]
        set log-all-url [enable|disable]
        set options {option1}, {option2}, ...
        config override
            Description: Web Filter override settings.
            set ovrd-cookie [allow|deny]
            set ovrd-scope [user|user-group|...]
            set profile-type [list|radius]
            set ovrd-dur-mode [constant|ask]
            set ovrd-dur {user}
            set profile-attribute [User-Name|NAS-IP-Address|...]
            set ovrd-user-group <name1>, <name2>, ...
            set profile <name1>, <name2>, ...
        end
        set ovrd-perm {option1}, {option2}, ...
        set post-action [normal|block]
        set replacemsg-group {string}
        config url-extraction
            Description: Configure URL Extraction
            set status [enable|disable]
            set server-fqdn {string}
            set redirect-header {string}
            set redirect-url {string}
            set redirect-no-content [enable|disable]
        end
        config web
            Description: Web content filtering settings.
            set bword-threshold {integer}
            set bword-table {integer}
            set urlfilter-table {integer}
            set content-header-list {integer}
            set blacklist [enable|disable]
            set whitelist {option1}, {option2}, ...
            set safe-search {option1}, {option2}, ...
            set youtube-restrict [none|strict|...]
            set log-search [enable|disable]
            set keyword-match <pattern1>, <pattern2>, ...
        end
        set web-content-log [enable|disable]
        set web-extended-all-action-log [enable|disable]
        set web-filter-activex-log [enable|disable]
        set web-filter-applet-log [enable|disable]
        set web-filter-command-block-log [enable|disable]
        set web-filter-cookie-log [enable|disable]
        set web-filter-cookie-removal-log [enable|disable]
        set web-filter-js-log [enable|disable]
        set web-filter-jscript-log [enable|disable]
        set web-filter-referer-log [enable|disable]
        set web-filter-unknown-log [enable|disable]
        set web-filter-vbs-log [enable|disable]
        set web-ftgd-err-log [enable|disable]
        set web-ftgd-quota-usage [enable|disable]
        set web-invalid-domain-log [enable|disable]
        set web-url-log [enable|disable]
        set wisp [enable|disable]
        set wisp-algorithm [primary-secondary|round-robin|...]
        set wisp-servers <name1>, <name2>, ...
        config youtube-channel-filter
            Description: YouTube channel filter.
            edit <id>
                set channel-id {string}
                set comment {var-string}
            next
        end
        set youtube-channel-status [disable|blacklist|...]
    next
end

config webfilter profile

Parameter

Description

Type

Size

comment

Optional comments.

var-string

Maximum length: 255

extended-log

Enable/disable extended logging for web filtering.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

https-replacemsg

Enable replacement messages for HTTPS.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

log-all-url

Enable/disable logging all URLs visited.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

name

Profile name.

string

Maximum length: 35

options

Options.

option

-

Option

Description

activexfilter

ActiveX filter.

cookiefilter

Cookie filter.

javafilter

Java applet filter.

block-invalid-url

Block sessions contained an invalid domain name.

jscript

Javascript block.

js

JS block.

vbs

VB script block.

unknown

Unknown script block.

intrinsic

Intrinsic script block.

wf-referer

Referring block.

wf-cookie

Cookie block.

per-user-bwl

Per-user black/white list filter

ovrd-perm

Permitted override types.

option

-

Option

Description

bannedword-override

Banned word override.

urlfilter-override

URL filter override.

fortiguard-wf-override

FortiGuard Web Filter override.

contenttype-check-override

Content-type header override.

post-action

Action taken for HTTP POST traffic.

option

-

Option

Description

normal

Normal, POST requests are allowed.

block

POST requests are blocked.

replacemsg-group

Replacement message group.

string

Maximum length: 35

web-content-log

Enable/disable logging logging blocked web content.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-extended-all-action-log

Enable/disable extended any filter action logging for web filtering.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-filter-activex-log

Enable/disable logging ActiveX.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-filter-applet-log

Enable/disable logging Java applets.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-filter-command-block-log

Enable/disable logging blocked commands.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-filter-cookie-log

Enable/disable logging cookie filtering.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-filter-cookie-removal-log

Enable/disable logging blocked cookies.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-filter-js-log

Enable/disable logging Java scripts.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-filter-jscript-log

Enable/disable logging JScripts.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-filter-referer-log

Enable/disable logging referrers.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-filter-unknown-log

Enable/disable logging unknown scripts.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-filter-vbs-log

Enable/disable logging VBS scripts.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-ftgd-err-log

Enable/disable logging rating errors.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-ftgd-quota-usage

Enable/disable logging daily quota usage.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-invalid-domain-log

Enable/disable logging invalid domain names.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-url-log

Enable/disable logging URL filtering.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

wisp

Enable/disable web proxy WISP.

option

-

Option

Description

enable

Enable web proxy WISP.

disable

Disable web proxy WISP.

wisp-algorithm

WISP server selection algorithm.

option

-

Option

Description

primary-secondary

Select the first healthy server in order.

round-robin

Select the next healthy server.

auto-learning

Select the lightest loading healthy server.

wisp-servers <name>

WISP servers.

Server name.

string

Maximum length: 79

youtube-channel-status

YouTube channel filter status.

option

-

Option

Description

disable

Disable YouTube channel filter.

blacklist

Block matches.

whitelist

Allow matches.

config file-filter

Parameter

Description

Type

Size

status

Enable/disable file filter.

option

-

Option

Description

enable

Enable file filter.

disable

Disable file filter.

log

Enable/disable file filter logging.

option

-

Option

Description

enable

Enable file filter logging.

disable

Disable file filter logging.

scan-archive-contents

Enable/disable file filter archive contents scan.

option

-

Option

Description

enable

Enable file filter archive contents scan.

disable

Disable file filter archive contents scan.

config entries

Parameter

Description

Type

Size

filter

Add a file filter.

string

Maximum length: 35

comment

Comment.

var-string

Maximum length: 255

protocol

Protocols to apply with.

option

-

Option

Description

http

Enable/disable HTTP.

ftp

Enable/disable FTP.

action

Action taken for matched file.

option

-

Option

Description

log

Allow the content and write a log message.

block

Block the content and write a log message.

direction

Match files transmitted in the session's originating or reply direction.

option

-

Option

Description

incoming

Match files transmitted in the session's originating direction.

outgoing

Match files transmitted in the session's reply direction.

any

Match files transmitted in the session's originating and reply direction.

password-protected

Match password-protected files.

option

-

Option

Description

yes

Match only password-protected files.

any

Match any file.

file-type <name>

Select file type.

File type name.

string

Maximum length: 39

config ftgd-wf

Parameter

Description

Type

Size

options

Options for FortiGuard Web Filter.

option

-

Option

Description

error-allow

Allow web pages with a rating error to pass through.

rate-server-ip

Rate the server IP in addition to the domain name.

connect-request-bypass

Bypass connection which has CONNECT request.

ftgd-disable

Disable FortiGuard scanning.

exempt-quota

Do not stop quota for these categories.

user

Not Specified

ovrd

Allow web filter profile overrides.

user

Not Specified

max-quota-timeout

Maximum FortiGuard quota used by single page view in seconds (excludes streams).

integer

Minimum value: 1 Maximum value: 86400

rate-image-urls

Enable/disable rating images by URL.

option

-

Option

Description

disable

Disable rating images by URL (blocked images are replaced with blanks).

enable

Enable rating images by URL (blocked images are replaced with blanks).

rate-javascript-urls

Enable/disable rating JavaScript by URL.

option

-

Option

Description

disable

Disable rating JavaScript by URL.

enable

Enable rating JavaScript by URL.

rate-css-urls

Enable/disable rating CSS by URL.

option

-

Option

Description

disable

Disable rating CSS by URL.

enable

Enable rating CSS by URL.

rate-crl-urls

Enable/disable rating CRL by URL.

option

-

Option

Description

disable

Disable rating CRL by URL.

enable

Enable rating CRL by URL.

config filters

Parameter

Description

Type

Size

id

ID number.

integer

Minimum value: 0 Maximum value: 255

category

Categories and groups the filter examines.

integer

Minimum value: 0 Maximum value: 255

action

Action to take for matches.

option

-

Option

Description

block

Block access.

authenticate

Authenticate user before allowing access.

monitor

Allow access while logging the action.

warning

Allow access after warning the user.

warn-duration

Duration of warnings.

user

Not Specified

auth-usr-grp <name>

Groups with permission to authenticate.

User group name.

string

Maximum length: 79

log

Enable/disable logging.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

override-replacemsg

Override replacement message.

string

Maximum length: 28

warning-prompt

Warning prompts in each category or each domain.

option

-

Option

Description

per-domain

Per-domain warnings.

per-category

Per-category warnings.

warning-duration-type

Re-display warning after closing browser or after a timeout.

option

-

Option

Description

session

After session ends.

timeout

After timeout occurs.

config quota

Parameter

Description

Type

Size

id

ID number.

integer

Minimum value: 0 Maximum value: 4294967295

category

FortiGuard categories to apply quota to (category action must be set to monitor).

user

Not Specified

type

Quota type.

option

-

Option

Description

time

Use a time-based quota.

traffic

Use a traffic-based quota.

unit

Traffic quota unit of measurement.

option

-

Option

Description

B

Quota in bytes.

KB

Quota in kilobytes.

MB

Quota in megabytes.

GB

Quota in gigabytes.

value

Traffic quota value.

integer

Minimum value: 1 Maximum value: 4294967295

duration

Duration of quota.

user

Not Specified

override-replacemsg

Override replacement message.

string

Maximum length: 28

config override

Parameter

Description

Type

Size

ovrd-cookie

Allow/deny browser-based (cookie) overrides.

option

-

Option

Description

allow

Allow browser-based (cookie) override.

deny

Deny browser-based (cookie) override.

ovrd-scope

Override scope.

option

-

Option

Description

user

Override for the user.

user-group

Override for the user's group.

ip

Override for the initiating IP.

browser

Create browser-based (cookie) override.

ask

Prompt for scope when initiating an override.

profile-type

Override profile type.

option

-

Option

Description

list

Profile chosen from list.

radius

Profile determined by RADIUS server.

ovrd-dur-mode

Override duration mode.

option

-

Option

Description

constant

Constant mode.

ask

Prompt for duration when initiating an override.

ovrd-dur

Override duration.

user

Not Specified

profile-attribute

Profile attribute to retrieve from the RADIUS server.

option

-

Option

Description

User-Name

Use this attribute.

NAS-IP-Address

Use this attribute.

Framed-IP-Address

Use this attribute.

Framed-IP-Netmask

Use this attribute.

Filter-Id

Use this attribute.

Login-IP-Host

Use this attribute.

Reply-Message

Use this attribute.

Callback-Number

Use this attribute.

Callback-Id

Use this attribute.

Framed-Route

Use this attribute.

Framed-IPX-Network

Use this attribute.

Class

Use this attribute.

Called-Station-Id

Use this attribute.

Calling-Station-Id

Use this attribute.

NAS-Identifier

Use this attribute.

Proxy-State

Use this attribute.

Login-LAT-Service

Use this attribute.

Login-LAT-Node

Use this attribute.

Login-LAT-Group

Use this attribute.

Framed-AppleTalk-Zone

Use this attribute.

Acct-Session-Id

Use this attribute.

Acct-Multi-Session-Id

Use this attribute.

ovrd-user-group <name>

User groups with permission to use the override.

User group name.

string

Maximum length: 79

profile <name>

Web filter profile with permission to create overrides.

Web profile.

string

Maximum length: 79

config url-extraction

Parameter

Description

Type

Size

status

Enable URL Extraction

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

server-fqdn

URL extraction server FQDN (fully qualified domain name)

string

Maximum length: 255

redirect-header

HTTP header name to use for client redirect on blocked requests

string

Maximum length: 35

redirect-url

HTTP header value to use for client redirect on blocked requests

string

Maximum length: 255

redirect-no-content

Enable / Disable empty message-body entity in HTTP response

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

config web

Parameter

Description

Type

Size

bword-threshold

Banned word score threshold.

integer

Minimum value: 0 Maximum value: 2147483647

bword-table

Banned word table ID.

integer

Minimum value: 0 Maximum value: 4294967295

urlfilter-table

URL filter table ID.

integer

Minimum value: 0 Maximum value: 4294967295

content-header-list

Content header list.

integer

Minimum value: 0 Maximum value: 4294967295

blacklist

Enable/disable automatic addition of URLs detected by FortiSandbox to blacklist.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

whitelist

FortiGuard whitelist settings.

option

-

Option

Description

exempt-av

Exempt antivirus.

exempt-webcontent

Exempt web content.

exempt-activex-java-cookie

Exempt ActiveX-JAVA-Cookie.

exempt-dlp

Exempt DLP.

exempt-rangeblock

Exempt RangeBlock.

extended-log-others

Support extended log.

safe-search

Safe search type.

option

-

Option

Description

url

Insert safe search string into URL.

header

Insert safe search header.

youtube-restrict

YouTube EDU filter level.

option

-

Option

Description

none

Full access for YouTube.

strict

Strict access for YouTube.

moderate

Moderate access for YouTube.

log-search

Enable/disable logging all search phrases.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

keyword-match <pattern>

Search keywords to log when match is found.

Pattern/keyword to search for.

string

Maximum length: 79

config youtube-channel-filter

Parameter

Description

Type

Size

id

ID.

integer

Minimum value: 0 Maximum value: 4294967295

channel-id

YouTube channel ID to be filtered.

string

Maximum length: 255

comment

Comment.

var-string

Maximum length: 255

config webfilter profile

Configure Web filter profiles.

config webfilter profile
    Description: Configure Web filter profiles.
    edit <name>
        set comment {var-string}
        set extended-log [enable|disable]
        config file-filter
            Description: File filter.
            set status [enable|disable]
            set log [enable|disable]
            set scan-archive-contents [enable|disable]
            config entries
                Description: File filter entries.
                edit <filter>
                    set comment {var-string}
                    set protocol {option1}, {option2}, ...
                    set action [log|block]
                    set direction [incoming|outgoing|...]
                    set password-protected [yes|any]
                    set file-type <name1>, <name2>, ...
                next
            end
        end
        config ftgd-wf
            Description: FortiGuard Web Filter settings.
            set options {option1}, {option2}, ...
            set exempt-quota {user}
            set ovrd {user}
            config filters
                Description: FortiGuard filters.
                edit <id>
                    set category {integer}
                    set action [block|authenticate|...]
                    set warn-duration {user}
                    set auth-usr-grp <name1>, <name2>, ...
                    set log [enable|disable]
                    set override-replacemsg {string}
                    set warning-prompt [per-domain|per-category]
                    set warning-duration-type [session|timeout]
                next
            end
            config quota
                Description: FortiGuard traffic quota settings.
                edit <id>
                    set category {user}
                    set type [time|traffic]
                    set unit [B|KB|...]
                    set value {integer}
                    set duration {user}
                    set override-replacemsg {string}
                next
            end
            set max-quota-timeout {integer}
            set rate-image-urls [disable|enable]
            set rate-javascript-urls [disable|enable]
            set rate-css-urls [disable|enable]
            set rate-crl-urls [disable|enable]
        end
        set https-replacemsg [enable|disable]
        set log-all-url [enable|disable]
        set options {option1}, {option2}, ...
        config override
            Description: Web Filter override settings.
            set ovrd-cookie [allow|deny]
            set ovrd-scope [user|user-group|...]
            set profile-type [list|radius]
            set ovrd-dur-mode [constant|ask]
            set ovrd-dur {user}
            set profile-attribute [User-Name|NAS-IP-Address|...]
            set ovrd-user-group <name1>, <name2>, ...
            set profile <name1>, <name2>, ...
        end
        set ovrd-perm {option1}, {option2}, ...
        set post-action [normal|block]
        set replacemsg-group {string}
        config url-extraction
            Description: Configure URL Extraction
            set status [enable|disable]
            set server-fqdn {string}
            set redirect-header {string}
            set redirect-url {string}
            set redirect-no-content [enable|disable]
        end
        config web
            Description: Web content filtering settings.
            set bword-threshold {integer}
            set bword-table {integer}
            set urlfilter-table {integer}
            set content-header-list {integer}
            set blacklist [enable|disable]
            set whitelist {option1}, {option2}, ...
            set safe-search {option1}, {option2}, ...
            set youtube-restrict [none|strict|...]
            set log-search [enable|disable]
            set keyword-match <pattern1>, <pattern2>, ...
        end
        set web-content-log [enable|disable]
        set web-extended-all-action-log [enable|disable]
        set web-filter-activex-log [enable|disable]
        set web-filter-applet-log [enable|disable]
        set web-filter-command-block-log [enable|disable]
        set web-filter-cookie-log [enable|disable]
        set web-filter-cookie-removal-log [enable|disable]
        set web-filter-js-log [enable|disable]
        set web-filter-jscript-log [enable|disable]
        set web-filter-referer-log [enable|disable]
        set web-filter-unknown-log [enable|disable]
        set web-filter-vbs-log [enable|disable]
        set web-ftgd-err-log [enable|disable]
        set web-ftgd-quota-usage [enable|disable]
        set web-invalid-domain-log [enable|disable]
        set web-url-log [enable|disable]
        set wisp [enable|disable]
        set wisp-algorithm [primary-secondary|round-robin|...]
        set wisp-servers <name1>, <name2>, ...
        config youtube-channel-filter
            Description: YouTube channel filter.
            edit <id>
                set channel-id {string}
                set comment {var-string}
            next
        end
        set youtube-channel-status [disable|blacklist|...]
    next
end

config webfilter profile

Parameter

Description

Type

Size

comment

Optional comments.

var-string

Maximum length: 255

extended-log

Enable/disable extended logging for web filtering.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

https-replacemsg

Enable replacement messages for HTTPS.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

log-all-url

Enable/disable logging all URLs visited.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

name

Profile name.

string

Maximum length: 35

options

Options.

option

-

Option

Description

activexfilter

ActiveX filter.

cookiefilter

Cookie filter.

javafilter

Java applet filter.

block-invalid-url

Block sessions contained an invalid domain name.

jscript

Javascript block.

js

JS block.

vbs

VB script block.

unknown

Unknown script block.

intrinsic

Intrinsic script block.

wf-referer

Referring block.

wf-cookie

Cookie block.

per-user-bwl

Per-user black/white list filter

ovrd-perm

Permitted override types.

option

-

Option

Description

bannedword-override

Banned word override.

urlfilter-override

URL filter override.

fortiguard-wf-override

FortiGuard Web Filter override.

contenttype-check-override

Content-type header override.

post-action

Action taken for HTTP POST traffic.

option

-

Option

Description

normal

Normal, POST requests are allowed.

block

POST requests are blocked.

replacemsg-group

Replacement message group.

string

Maximum length: 35

web-content-log

Enable/disable logging logging blocked web content.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-extended-all-action-log

Enable/disable extended any filter action logging for web filtering.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-filter-activex-log

Enable/disable logging ActiveX.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-filter-applet-log

Enable/disable logging Java applets.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-filter-command-block-log

Enable/disable logging blocked commands.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-filter-cookie-log

Enable/disable logging cookie filtering.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-filter-cookie-removal-log

Enable/disable logging blocked cookies.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-filter-js-log

Enable/disable logging Java scripts.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-filter-jscript-log

Enable/disable logging JScripts.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-filter-referer-log

Enable/disable logging referrers.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-filter-unknown-log

Enable/disable logging unknown scripts.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-filter-vbs-log

Enable/disable logging VBS scripts.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-ftgd-err-log

Enable/disable logging rating errors.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-ftgd-quota-usage

Enable/disable logging daily quota usage.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-invalid-domain-log

Enable/disable logging invalid domain names.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

web-url-log

Enable/disable logging URL filtering.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

wisp

Enable/disable web proxy WISP.

option

-

Option

Description

enable

Enable web proxy WISP.

disable

Disable web proxy WISP.

wisp-algorithm

WISP server selection algorithm.

option

-

Option

Description

primary-secondary

Select the first healthy server in order.

round-robin

Select the next healthy server.

auto-learning

Select the lightest loading healthy server.

wisp-servers <name>

WISP servers.

Server name.

string

Maximum length: 79

youtube-channel-status

YouTube channel filter status.

option

-

Option

Description

disable

Disable YouTube channel filter.

blacklist

Block matches.

whitelist

Allow matches.

config file-filter

Parameter

Description

Type

Size

status

Enable/disable file filter.

option

-

Option

Description

enable

Enable file filter.

disable

Disable file filter.

log

Enable/disable file filter logging.

option

-

Option

Description

enable

Enable file filter logging.

disable

Disable file filter logging.

scan-archive-contents

Enable/disable file filter archive contents scan.

option

-

Option

Description

enable

Enable file filter archive contents scan.

disable

Disable file filter archive contents scan.

config entries

Parameter

Description

Type

Size

filter

Add a file filter.

string

Maximum length: 35

comment

Comment.

var-string

Maximum length: 255

protocol

Protocols to apply with.

option

-

Option

Description

http

Enable/disable HTTP.

ftp

Enable/disable FTP.

action

Action taken for matched file.

option

-

Option

Description

log

Allow the content and write a log message.

block

Block the content and write a log message.

direction

Match files transmitted in the session's originating or reply direction.

option

-

Option

Description

incoming

Match files transmitted in the session's originating direction.

outgoing

Match files transmitted in the session's reply direction.

any

Match files transmitted in the session's originating and reply direction.

password-protected

Match password-protected files.

option

-

Option

Description

yes

Match only password-protected files.

any

Match any file.

file-type <name>

Select file type.

File type name.

string

Maximum length: 39

config ftgd-wf

Parameter

Description

Type

Size

options

Options for FortiGuard Web Filter.

option

-

Option

Description

error-allow

Allow web pages with a rating error to pass through.

rate-server-ip

Rate the server IP in addition to the domain name.

connect-request-bypass

Bypass connection which has CONNECT request.

ftgd-disable

Disable FortiGuard scanning.

exempt-quota

Do not stop quota for these categories.

user

Not Specified

ovrd

Allow web filter profile overrides.

user

Not Specified

max-quota-timeout

Maximum FortiGuard quota used by single page view in seconds (excludes streams).

integer

Minimum value: 1 Maximum value: 86400

rate-image-urls

Enable/disable rating images by URL.

option

-

Option

Description

disable

Disable rating images by URL (blocked images are replaced with blanks).

enable

Enable rating images by URL (blocked images are replaced with blanks).

rate-javascript-urls

Enable/disable rating JavaScript by URL.

option

-

Option

Description

disable

Disable rating JavaScript by URL.

enable

Enable rating JavaScript by URL.

rate-css-urls

Enable/disable rating CSS by URL.

option

-

Option

Description

disable

Disable rating CSS by URL.

enable

Enable rating CSS by URL.

rate-crl-urls

Enable/disable rating CRL by URL.

option

-

Option

Description

disable

Disable rating CRL by URL.

enable

Enable rating CRL by URL.

config filters

Parameter

Description

Type

Size

id

ID number.

integer

Minimum value: 0 Maximum value: 255

category

Categories and groups the filter examines.

integer

Minimum value: 0 Maximum value: 255

action

Action to take for matches.

option

-

Option

Description

block

Block access.

authenticate

Authenticate user before allowing access.

monitor

Allow access while logging the action.

warning

Allow access after warning the user.

warn-duration

Duration of warnings.

user

Not Specified

auth-usr-grp <name>

Groups with permission to authenticate.

User group name.

string

Maximum length: 79

log

Enable/disable logging.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

override-replacemsg

Override replacement message.

string

Maximum length: 28

warning-prompt

Warning prompts in each category or each domain.

option

-

Option

Description

per-domain

Per-domain warnings.

per-category

Per-category warnings.

warning-duration-type

Re-display warning after closing browser or after a timeout.

option

-

Option

Description

session

After session ends.

timeout

After timeout occurs.

config quota

Parameter

Description

Type

Size

id

ID number.

integer

Minimum value: 0 Maximum value: 4294967295

category

FortiGuard categories to apply quota to (category action must be set to monitor).

user

Not Specified

type

Quota type.

option

-

Option

Description

time

Use a time-based quota.

traffic

Use a traffic-based quota.

unit

Traffic quota unit of measurement.

option

-

Option

Description

B

Quota in bytes.

KB

Quota in kilobytes.

MB

Quota in megabytes.

GB

Quota in gigabytes.

value

Traffic quota value.

integer

Minimum value: 1 Maximum value: 4294967295

duration

Duration of quota.

user

Not Specified

override-replacemsg

Override replacement message.

string

Maximum length: 28

config override

Parameter

Description

Type

Size

ovrd-cookie

Allow/deny browser-based (cookie) overrides.

option

-

Option

Description

allow

Allow browser-based (cookie) override.

deny

Deny browser-based (cookie) override.

ovrd-scope

Override scope.

option

-

Option

Description

user

Override for the user.

user-group

Override for the user's group.

ip

Override for the initiating IP.

browser

Create browser-based (cookie) override.

ask

Prompt for scope when initiating an override.

profile-type

Override profile type.

option

-

Option

Description

list

Profile chosen from list.

radius

Profile determined by RADIUS server.

ovrd-dur-mode

Override duration mode.

option

-

Option

Description

constant

Constant mode.

ask

Prompt for duration when initiating an override.

ovrd-dur

Override duration.

user

Not Specified

profile-attribute

Profile attribute to retrieve from the RADIUS server.

option

-

Option

Description

User-Name

Use this attribute.

NAS-IP-Address

Use this attribute.

Framed-IP-Address

Use this attribute.

Framed-IP-Netmask

Use this attribute.

Filter-Id

Use this attribute.

Login-IP-Host

Use this attribute.

Reply-Message

Use this attribute.

Callback-Number

Use this attribute.

Callback-Id

Use this attribute.

Framed-Route

Use this attribute.

Framed-IPX-Network

Use this attribute.

Class

Use this attribute.

Called-Station-Id

Use this attribute.

Calling-Station-Id

Use this attribute.

NAS-Identifier

Use this attribute.

Proxy-State

Use this attribute.

Login-LAT-Service

Use this attribute.

Login-LAT-Node

Use this attribute.

Login-LAT-Group

Use this attribute.

Framed-AppleTalk-Zone

Use this attribute.

Acct-Session-Id

Use this attribute.

Acct-Multi-Session-Id

Use this attribute.

ovrd-user-group <name>

User groups with permission to use the override.

User group name.

string

Maximum length: 79

profile <name>

Web filter profile with permission to create overrides.

Web profile.

string

Maximum length: 79

config url-extraction

Parameter

Description

Type

Size

status

Enable URL Extraction

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

server-fqdn

URL extraction server FQDN (fully qualified domain name)

string

Maximum length: 255

redirect-header

HTTP header name to use for client redirect on blocked requests

string

Maximum length: 35

redirect-url

HTTP header value to use for client redirect on blocked requests

string

Maximum length: 255

redirect-no-content

Enable / Disable empty message-body entity in HTTP response

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

config web

Parameter

Description

Type

Size

bword-threshold

Banned word score threshold.

integer

Minimum value: 0 Maximum value: 2147483647

bword-table

Banned word table ID.

integer

Minimum value: 0 Maximum value: 4294967295

urlfilter-table

URL filter table ID.

integer

Minimum value: 0 Maximum value: 4294967295

content-header-list

Content header list.

integer

Minimum value: 0 Maximum value: 4294967295

blacklist

Enable/disable automatic addition of URLs detected by FortiSandbox to blacklist.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

whitelist

FortiGuard whitelist settings.

option

-

Option

Description

exempt-av

Exempt antivirus.

exempt-webcontent

Exempt web content.

exempt-activex-java-cookie

Exempt ActiveX-JAVA-Cookie.

exempt-dlp

Exempt DLP.

exempt-rangeblock

Exempt RangeBlock.

extended-log-others

Support extended log.

safe-search

Safe search type.

option

-

Option

Description

url

Insert safe search string into URL.

header

Insert safe search header.

youtube-restrict

YouTube EDU filter level.

option

-

Option

Description

none

Full access for YouTube.

strict

Strict access for YouTube.

moderate

Moderate access for YouTube.

log-search

Enable/disable logging all search phrases.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

keyword-match <pattern>

Search keywords to log when match is found.

Pattern/keyword to search for.

string

Maximum length: 79

config youtube-channel-filter

Parameter

Description

Type

Size

id

ID.

integer

Minimum value: 0 Maximum value: 4294967295

channel-id

YouTube channel ID to be filtered.

string

Maximum length: 255

comment

Comment.

var-string

Maximum length: 255