Course menu

Module 6: Security ProfilesLesson 6.3 (3 of 6 in this module)26 of 33 in the FortiGate Administrator course

Web filtering and DNS filtering

FortiGuard categories and their actions, static URL filters, rating overrides, safe search, and blocking at DNS with a DNS filter.

Intermediate · 12 min read

What you will learn

After this lesson, you can build a web filter profile with category actions and a static URL filter, override a wrong rating, block at DNS with a DNS filter, and read the web filter logs.

  • FortiGuard categories
  • URL filter
  • Overrides
  • DNS filter

Web filtering controls which websites users can reach. A FortiGate web filter profile looks up each requested site's FortiGuard category (such as Phishing, Malicious Websites or Gambling) and applies the action chosen for that category; static URL filters and local rating overrides handle exceptions. A DNS filter applies the same categories earlier, when the name is resolved.

In simple terms: Every website has a label, like 'gambling' or 'news'. You choose which labels are allowed, blocked or warned about, and add your own exceptions.

A real-life situation

Management wants gambling and adult sites blocked, a warning on social media, and every phishing and malware site stopped. Marketing then complains their analytics tool is blocked as "Newly Observed Domain". A web filter profile handles both: categories for the broad policy, URL filters and overrides for the exceptions.

How a request is checked

1. Static URL filter
Your list first: exempt, allow, block or monitor for a matching URL.
2. FortiGuard category
Look up the rating (or a local override), apply that category's action.
3. Other options
Safe search, quotas, content checks (with the right inspection).
The order a web filter profile uses. The first decision stops the checks.

Category actions

Simplified illustration of the FortiOS 7.4 GUI · not a screenshot
FGT1Security Profiles › Web Filter

Edit Web Filter Profile: Staff-WF

FortiGuard Category Based Filter

Security Risk
Block (Phishing, Malicious Websites…)
Gambling
Block
Adult / Mature Content
Block
Social Networking
WarningUsers see a warning page and can continue.
Unrated
Block
All other categories
Monitor (log, allow)

Static URL Filter

URL Filter
On1 entry

Search Engines

Enforce safe search
On
ActionWhat the user gets
AllowThe page, not logged
MonitorThe page, and a log entry
WarningA warning page with a Proceed button
AuthenticateA login; allowed only for listed user groups
BlockA block page (replacement message)

Exceptions: static URL filter and overrides

config webfilter urlfilter edit 1 set name "Staff-URLs" config entries edit 1 set url "analytics.example-tool.com" set type simple set action exempt next edit 2 set url "*.example-games.com" set type wildcard set action block next end next end config webfilter profile edit "Staff-WF" config web set urlfilter-table 1 end next end

Static URL entries are checked before categories. Exempt skips the remaining web filter checks for that URL (and other scans you choose); allow only skips the category check. Wildcard and regex entries match many URLs; keep them tight.

If FortiGuard simply has a site in the wrong category, a rating override (Security Profiles › Web Rating Overrides) gives it a different category on your FortiGate, and you can submit the site to Fortinet for re-rating.

DNS filtering

A DNS filter profile on the same policy checks each DNS query's category. Blocked domains get an answer pointing to the FortiGate's block page, or a refusal, so the connection never starts. It also blocks known botnet command-and-control domains. It only works when the clients' DNS queries pass through the FortiGate (or use it as their DNS server).

Verify

Example output · based on Fortinet documentation; exact format varies by model and FortiOS version
FGT1 # diagnose debug rating
Locale       : english

Service      : Web-filter
Status       : Enable
License      : Contract

Service      : Antispam
Status       : Disable

Num. of servers : 1
Protocol        : https
Port            : 443
...
Shows whether web filtering is licensed and which FortiGuard servers the FortiGate uses for ratings. (Example output, trimmed.) Blocked and warned requests appear under Log & Report › Security Events › Web Filter, with the category and policy ID.

Why it works this way

No one can list every website, so categories maintained by a provider do the bulk of the work. Your own URL filters come first because local knowledge beats a global rating: you know which tool marketing needs.

Common mistakes

  • Expecting full-URL filtering of HTTPS sites under certificate inspection: only the domain is visible.
  • Broad exempt entries (*.com-style wildcards) that switch inspection off far beyond the intended site.
  • Clients using DNS-over-HTTPS or an outside resolver, bypassing the DNS filter.
  • Blocking "Unrated" without a plan for new internal or partner sites.

Key takeaways

✅ Key takeaways
  • Static URL filter first, then FortiGuard categories with allow, monitor, warning, authenticate or block.
  • Exempt, allow and block URL entries handle exceptions; rating overrides fix wrong categories.
  • DNS filtering blocks whole domains at lookup time, for all applications.
  • Check ratings with diagnose debug rating and the Web Filter security log.

Check yourself

Predict · scenario 1

Gambling is set to Block, and a static URL filter entry exempts casino.example. Can users open casino.example?

Predict · scenario 2

Which category action lets the user continue after reading a notice?

Predict · scenario 3

A laptop app (not a browser) connects to a known malware domain. Which profile can stop it even without deep inspection?

FAQ

Why does a blocked category still load sometimes?
Common causes: the traffic matched a different policy without the profile, the site is exempted by a static URL filter, the FortiGate can't reach FortiGuard for ratings (check the 'rating error' action), or the content comes from a different domain, such as a CDN, with another category.
Web filter or DNS filter?
Both. DNS filtering is light and stops connections before they start, even for apps and non-web protocols, but works on whole domains only. The web filter sees full URLs (with deep inspection) and can show block pages for HTTPS sites.