{"id":55668,"date":"2020-01-25T00:00:00","date_gmt":"2020-01-24T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/6-fortinet-getting-started-v6-0-web-filtering-i-application-control"},"modified":"2020-02-18T14:03:48","modified_gmt":"2020-02-18T11:03:48","slug":"6-fortinet-getting-started-v6-0-web-filtering-i-application-control","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/6-fortinet-getting-started-v6-0-web-filtering-i-application-control","title":{"rendered":"6. Fortinet Getting Started v6.0. Web Filtering and Application Control","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"6. Fortinet Getting Started v6.0. Web Filtering and Application Control\" src=\"\/wp-content\/uploads\/2020\/01\/186987e73a093c7af70bd397a6b3c0d4.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nWelcome! You are in the sixth lesson of the course <noindex><a rel=\"nofollow\" href=\"https:\/\/fortiservice.com\/news\/fortinet-getting-started-vvedenie\/\">Fortinet Getting Started<\/a><\/noindex>. On <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/484072\/\">previous lesson<\/a><\/noindex> we have mastered the basics of working with NAT technology on <noindex><a rel=\"nofollow\" href=\"https:\/\/fortiservice.com\/catalog\/fortigate\/\">FortiGate<\/a><\/noindex>, and we have also released our test user to the Internet. Now it\u2019s time to ensure the user's security in this vast space. In this lesson, we will explore the following security profiles: Web Filtering, Application Control, and HTTPS inspection.<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<p>To start getting acquainted with security profiles, we need to understand one more thing\u2014inspection modes. <\/p>\n<p><img decoding=\"async\" alt=\"6. Fortinet Getting Started v6.0. Web Filtering and Application Control\" src=\"\/wp-content\/uploads\/2020\/01\/bf2e137fa1839c9ef2a5764c5e731124.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nBy default, Flow Based mode is used. It checks files as they pass through FortiGate without buffering. As soon as the packet arrives, it is processed and forwarded without waiting for the entire file or webpage. It requires fewer resources and provides higher performance than Proxy mode, but not all security functionalities are available in it. For example, data loss prevention (DLP) can only be used in Proxy mode.<br \/>\nProxy mode works differently. It creates two TCP connections, one between the client and FortiGate, the other between FortiGate and the server. This allows it to buffer traffic, meaning it can receive the entire file or webpage. Scanning files for various threats begins only after the whole file has been buffered. This allows for additional capabilities that are not available in Flow Based mode. As you can see, this mode is somewhat the opposite of Flow Based\u2014security is the main focus here, while performance takes a back seat.<br \/>\nPeople often ask\u2014 which mode is better? However, there is no universal answer. It is always individual and depends on your needs and objectives. I will further demonstrate the differences between security profiles in Flow and Proxy modes throughout the course. This will help you compare functionalities and decide which one suits you best. <\/p>\n<p>Let\u2019s move on to the security profiles and first explore Web Filtering. It helps control or monitor which websites users visit. I believe there is no need to delve into the necessity of such a profile in today's reality. Let\u2019s find out how it works.<\/p>\n<p><img decoding=\"async\" alt=\"6. Fortinet Getting Started v6.0. Web Filtering and Application Control\" src=\"\/wp-content\/uploads\/2020\/01\/af05db55464cc90b4fe70b8b5efc0937.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nOnce a TCP connection is established, the user requests content from a specific website using a GET request.<\/p>\n<p>If the web server responds positively, it sends the information about the website in reply. This is where the web filter comes into play. It checks the content of this response. During this check, FortiGate sends a request in real-time to the FortiGuard Distribution Network (FDN) to determine the category of the website. Once the category of the specific website is identified, the web filter takes specific actions based on settings. <br \/>\nIn Flow mode, three actions are available: <\/p>\n<ul>\n<li>Allow \u2014 permit access to the website<\/li>\n<li>Block \u2014 deny access to the website<\/li>\n<li>Monitor \u2014 allow access to the website and log this action<\/li>\n<\/ul>\n<p>\nIn Proxy mode, two additional actions are available: <\/p>\n<ul>\n<li>Warning \u2014 issue a warning to the user that they are attempting to visit a specific resource and give them the choice to continue or leave the website<\/li>\n<li>Authenticate \u2014 request user credentials \u2014 this allows certain groups to gain access to blocked categories of websites. <\/li>\n<\/ul>\n<p>\nOn the website <noindex><a rel=\"nofollow\" href=\"https:\/\/fortiguard.com\/webfilter%E2%80%9C%E2%80%9D\">FortiGuard Labs<\/a><\/noindex> you can explore all categories and subcategories of the web filter, as well as find out to which category a specific website belongs. In general, for users of Fortinet solutions, this is quite a useful site; I recommend checking it out in your free time.<\/p>\n<p>Not much can be said about Application Control. As the name suggests, it allows for controlling application usage. It does this using patterns of various applications, known as signatures. Based on these signatures, it can identify specific applications and apply certain actions to them:<\/p>\n<ul>\n<li>Allow \u2014 permit<\/li>\n<li>Monitor \u2014 allow and log this action<\/li>\n<li>Block \u2014 deny<\/li>\n<li>Quarantine \u2014 log the event and block the IP address for a specified time<\/li>\n<\/ul>\n<p>\nYou can also view existing signatures on the website <noindex><a rel=\"nofollow\" href=\"https:\/\/fortiguard.com\/appcontrol\">FortiGuard Labs<\/a><\/noindex>. <\/p>\n<p><img decoding=\"async\" alt=\"6. Fortinet Getting Started v6.0. Web Filtering and Application Control\" src=\"\/wp-content\/uploads\/2020\/01\/c36d9ad2cddc88499f4fff8b8c15df8d.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nNow let's examine the HTTPS inspection mechanism. According to statistics from the end of 2018, the share of HTTPS traffic exceeded 70%. This means that without using HTTPS inspection, we will only be able to analyze about 30% of the traffic flowing through the network. First, let's look at how HTTPS works in broad strokes.<\/p>\n<p>The client initiates a TLS request to the web server and receives a TLS response, along with a digital certificate that must be trusted by the user. This is the essential information we need to know about how HTTPS works; in reality, its mechanics are much more complex. After a successful TLS handshake, data transmission begins in an encrypted format. This is beneficial, as no one can access the data exchanged with the web server. <\/p>\n<p><img decoding=\"async\" alt=\"6. Fortinet Getting Started v6.0. Web Filtering and Application Control\" src=\"\/wp-content\/uploads\/2020\/01\/cd9227c6f1f19d508c95e7f4ff9a577c.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nHowever, for corporate security professionals, this poses a significant headache, as they cannot see this traffic or inspect its content using antivirus software, intrusion prevention systems, DLP systems, or anything else. This also negatively impacts the quality of application and web resource identification within the network \u2014 precisely the topic of our lesson. The technology designed to address this issue is HTTPS inspection. Its essence is quite simple \u2014 basically, the device performing HTTPS inspection orchestrates a Man In The Middle attack. It looks something like this: FortiGate intercepts the user's request, establishes an HTTPS connection with it, and then initiates an HTTPS session with the resource the user requested. The user\u2019s computer will display a certificate issued by FortiGate, which must be trusted for the browser to allow the connection. <\/p>\n<p><img decoding=\"async\" alt=\"6. Fortinet Getting Started v6.0. Web Filtering and Application Control\" src=\"\/wp-content\/uploads\/2020\/01\/1d66da813ea9aad17e25c55554271215.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nIn fact, HTTPS inspection is quite a complex matter and has numerous limitations, but we will not discuss this in the context of this course. I will just add that implementing HTTPS inspection is not a quick task; it typically takes about a month. It is necessary to gather information about required exceptions, make the appropriate settings, collect user feedback, and adjust the settings. <\/p>\n<p>The theoretical content, as well as the practical part, is presented in this video lesson:<\/p>\n<p><center><div class=\"youtube-placeholder\" data-id=\"yyEhxOAU0L8\" onclick=\"loadVideo(this)\">\r\n        <img decoding=\"async\" src=\"https:\/\/img.youtube.com\/vi\/yyEhxOAU0L8\/hqdefault.jpg\" alt=\"Play video\" loading=\"lazy\" width=\"480\" height=\"360\" style=\"width:100%;height:auto;\">\r\n        <div class=\"play-button\"><\/div>\r\n    <\/div><\/center><\/p>\n<p>In the next lesson, we will explore other security profiles: antivirus and intrusion prevention systems. To avoid missing it, keep an eye on updates from the following channels:<\/p>\n<ul>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/channel\/UCKOESE8nBWQPuQmi994_YMA\">Youtube<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/vk.com\/fortiservice\">VK Group<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/zen.yandex.ru\/id\/5c7d2162fa818600ae386a52\">Yandex Zen <\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/fortiservice.com\/\">Our website<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.t.me\/tssolution\">Telegram channel<\/a><\/noindex><\/li>\n<\/ul>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/484814\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u0440\u0438\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e! \u0414\u043e\u0431\u0440\u043e \u043f\u043e\u0436\u0430\u043b\u043e\u0432\u0430\u0442\u044c \u043d\u0430 \u0448\u0435\u0441\u0442\u043e\u0439 \u0443\u0440\u043e\u043a \u043a\u0443\u0440\u0441\u0430 Fortinet Getting Started. \u041d\u0430 \u043f\u0440\u043e\u0448\u043b\u043e\u043c \u0443\u0440\u043e\u043a\u0435 \u043c\u044b \u043e\u0441\u0432\u043e\u0438\u043b\u0438 \u043e\u0441\u043d\u043e\u0432\u044b \u0440\u0430\u0431\u043e\u0442\u044b \u0441 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0435\u0439 NAT \u043d\u0430 FortiGate, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0432\u044b\u043f\u0443\u0441\u0442\u0438\u043b\u0438 \u043d\u0430\u0448\u0435\u0433\u043e \u0442\u0435\u0441\u0442\u043e\u0432\u043e\u0433\u043e \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0432 \u0418\u043d\u0442\u0435\u0440\u043d\u0435\u0442. \u0422\u0435\u043f\u0435\u0440\u044c \u043f\u0440\u0438\u0448\u043b\u043e \u0432\u0440\u0435\u043c\u044f \u043f\u043e\u0437\u0430\u0431\u043e\u0442\u0438\u0442\u044c\u0441\u044f \u043e \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u043d\u0430 \u0435\u0433\u043e \u043f\u0440\u043e\u0441\u0442\u043e\u0440\u0430\u0445. \u0412 \u0434\u0430\u043d\u043d\u043e\u043c \u0443\u0440\u043e\u043a\u0435 \u043c\u044b \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0438\u043c \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0435 \u043f\u0440\u043e\u0444\u0438\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438: Web Filtering, Application Control, \u0430 \u0442\u0430\u043a\u0436\u0435 HTTPS [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-55668","post","type-post","status-publish","format-standard","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u0440\u0438\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e!\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/6-fortinet-getting-started-v6-0-web-filtering-i-application-control\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd476. Fortinet Getting Started v6.0. Web Filtering \u0438 Application Control | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u0440\u0438\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e!\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/6-fortinet-getting-started-v6-0-web-filtering-i-application-control\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-01-24T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:03:48+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd476. Fortinet Getting Started v6.0. Web Filtering and Application Control | ProHoster","description":"Hello!","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/6-fortinet-getting-started-v6-0-web-filtering-i-application-control","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd476. Fortinet Getting Started v6.0. Web Filtering \u0438 Application Control | ProHoster","og:description":"\u041f\u0440\u0438\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e!","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/6-fortinet-getting-started-v6-0-web-filtering-i-application-control","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-01-24T21:00:00+00:00","article:modified_time":"2020-02-18T11:03:48+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"55668","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 14:06:06","updated":"2022-09-27 18:46:15","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/55668","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=55668"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/55668\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=55668"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=55668"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=55668"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}