In this blog I'll go through how I configure my lab environment so that computer/users will automatically connect to web servers via a text document on a schedule. The reason I set this up is to simulate constant 'real world' browsing from computers in the lab so that my web filtering reports are filled up when it comes time to demo to customers!
Showing posts with label web filter. Show all posts
Showing posts with label web filter. Show all posts
Friday, 21 August 2015
How-to: Automate user browsing from a text file containing URLs
Labels:
fortianalyzer,
fortigate,
how-to,
script,
web filter,
wget,
windows
Monday, 15 September 2014
How-to: Configure Quotas by Data Usage on a FortiGate
Long ago, you had two options when it came to usage quotas on the FortiGate; it was either based on data usage, or time usage. Fortinet then decided to remove the data usage quota and only have time based ones available. Recently Fortinet have decided to reintroduce the data based quotas (albeit it can only be configured via the CLI).
We'll go through creating a data usage quota on a web filtering profile, and some things you should know.
We'll go through creating a data usage quota on a web filtering profile, and some things you should know.
Labels:
bandwidth,
cli,
config,
fortigate,
FortiOS 5.2,
how-to,
quota,
web filter
Tuesday, 15 October 2013
How-to: Get DropBox working on a FortiGate with SSL Deep Packet Inspection enabled
SSL Deep Packet Inspection (DPI) allows the FortiGate to decrypt and scan all HTTPS, SMTPS, POPS, IMAPS and FTPS sessions. It then re-encrypts and sends the packets off on their merry way (essentially a man in the middle attack).
I've recently enabled it in my lab and noticed that my DropBox kept on disconnecting. I suspect it's something to do with FortiGate certificate not being trusted in DropBox which would give an error.
The way I got around this is to enable the web site filter and excempt the dropbox.com domain from the webfilter (and DPI).
To set this up goto Security Policies > Web Filter > Profiles and edit the webfilter profile used in your web policy.
Next enable " and add the dropbox.com domain (simple, exempt & enabled). Click 'Apply' to save.
Now try to log back into DropBox and you should see the status come up as connected!
I've recently enabled it in my lab and noticed that my DropBox kept on disconnecting. I suspect it's something to do with FortiGate certificate not being trusted in DropBox which would give an error.
The way I got around this is to enable the web site filter and excempt the dropbox.com domain from the webfilter (and DPI).
To set this up goto Security Policies > Web Filter > Profiles and edit the webfilter profile used in your web policy.
Next enable " and add the dropbox.com domain (simple, exempt & enabled). Click 'Apply' to save.
Now try to log back into DropBox and you should see the status come up as connected!
Labels:
application control,
dropbox,
fortigate,
FortiOS 5,
how-to,
web filter
Subscribe to:
Posts (Atom)
