I’ve been trying to tackle a somewhat annoying issue of users being able to access blocked websites via https. We can’t block https flat out since most of our work environment is Google Apps.<\/p>\n
Advertisement
Essentially we are just looking for a way to block https to specific URLs. I think at most we want to block 5 websites that can be bypassed via https, so this doesn’t really warrant us to turn on the SSL inspection policy that would literally block all incoming/outgoing https connections.<\/p>\n
Questions:<\/p>\n
\n
Can this be done on a specific URL level on the fortigate?<\/li>\n
Can this be done on the computers? If it can, what are the steps?<\/li>\n
Can this be done in AD? If so, what are the steps?<\/li>\n<\/ul>\n
Firewall territory is somewhat new to me. Thanks for any help in advance. If this question is on the wrong area, please feel free to close it or move it.<\/p>","upvoteCount":2,"answerCount":18,"datePublished":"2016-09-06T17:24:47.000Z","author":{"@type":"Person","name":"matt7744","url":"https://community.spiceworks.com/u/matt7744"},"acceptedAnswer":{"@type":"Answer","text":"
For filters using flow mode, you do have to use SSL inspection to block HTTPS.<\/p>\n
It’s not ideal, but you could distribute the builtin Fortigate cert as trusted to all of the devices that are managed using GPO or some other deployment method.<\/p>\n
The other option, if we are talking about a handful of sites, is to poison your internal dns by creating entries for the domains you wish to block. You can forward the traffic to nothing or to a page that shows the Web usage policy or whatever you want.<\/p>\n
Technically someone could get around this by using the IP of the website or putting something in their hosts file, but DNS poisoning would cover about 99% of a normal user base.<\/p>","upvoteCount":0,"datePublished":"2016-09-09T17:02:28.000Z","url":"https://community.spiceworks.com/t/fortigate-500d-https-issue/523610/15","author":{"@type":"Person","name":"daveanderson3","url":"https://community.spiceworks.com/u/daveanderson3"}},"suggestedAnswer":[{"@type":"Answer","text":"
Hello!<\/p>\n
I’ve been trying to tackle a somewhat annoying issue of users being able to access blocked websites via https. We can’t block https flat out since most of our work environment is Google Apps.<\/p>\n
Essentially we are just looking for a way to block https to specific URLs. I think at most we want to block 5 websites that can be bypassed via https, so this doesn’t really warrant us to turn on the SSL inspection policy that would literally block all incoming/outgoing https connections.<\/p>\n
Questions:<\/p>\n
\n
Can this be done on a specific URL level on the fortigate?<\/li>\n
Can this be done on the computers? If it can, what are the steps?<\/li>\n
Can this be done in AD? If so, what are the steps?<\/li>\n<\/ul>\n
Firewall territory is somewhat new to me. Thanks for any help in advance. If this question is on the wrong area, please feel free to close it or move it.<\/p>","upvoteCount":2,"datePublished":"2016-09-06T17:24:47.000Z","url":"https://community.spiceworks.com/t/fortigate-500d-https-issue/523610/1","author":{"@type":"Person","name":"matt7744","url":"https://community.spiceworks.com/u/matt7744"}},{"@type":"Answer","text":"
If you have a paid subscription with Fortigate I want to say that you can visit their website to input a trouble ticket and they will give you the steps. In some instances they will even screen share with you.<\/p>","upvoteCount":0,"datePublished":"2016-09-06T18:47:18.000Z","url":"https://community.spiceworks.com/t/fortigate-500d-https-issue/523610/2","author":{"@type":"Person","name":"kamsalisbury","url":"https://community.spiceworks.com/u/kamsalisbury"}},{"@type":"Answer","text":"
You could create a policy that would block port 443 to those domain names.<\/p>","upvoteCount":0,"datePublished":"2016-09-06T19:54:06.000Z","url":"https://community.spiceworks.com/t/fortigate-500d-https-issue/523610/3","author":{"@type":"Person","name":"steve4970","url":"https://community.spiceworks.com/u/steve4970"}},{"@type":"Answer","text":"