Refer to the exhibit, which shows a partial web filter profile configuration. Which action will FortiGate take if a user attempts to access www.dropbox.com, which is categorized as File Sharing and Storage?
A.
FortiGate will block the connection, based on the FortiGuard category based filter configuration.
B.
FortiGate will block the connection as an invalid URL.
C.
FortiGate will exempt the connection, based on the Web Content Filter configuration.
D.
FortiGate will allow the connection, based onthe URL Filter configuration.
Coorect! If with "allow" action the next step is to check FortiGuard category. If the category action is "block" the connection is blocked.
Correct answer is A
So, I didn’t find this is the training material, however it’s specified on Fortinet.com, correct answer is A.
When FortiGate performs a web filter check, it will first check the static URL filter list (if applied to the profile) and based on the action, will then perform the FortiGuard category check.
'Action' descriptions in Static URL see bellow:
- 'Block' -> destination is blocked and session dropped, no further category check is needed.
- 'Allow' -> destination is allowed from the static URL list, FortiGate proceeds with checking the category to decide further action.
- 'Exempt' -> destination is exempted from further inspection and traffic is allowed.
- https://community.fortinet.com/t5/FortiGate/Technical-Tip-Difference-between-action-Allow-and-Exempt-in/ta-p/231334
Answer - A -
- 'Allow' -> destination is allowed from the static URL list, FortiGate proceeds with checking the category to decide further action. - 'Exempt' -> destination is exempted from further inspection and traffic is allowed.
Order of operation is:
1. URL filter
2. FortiGuard Web Filtering
3. Web content filter
4. Web script filter
5. Antivirus scanning
URL filter = ALLOW continues to evaluate the next steps, incl. Web Filtering.
If it is required to Allow access to a site regardless of the category, then use "Exempt".
https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-Static-URL-filter-actions-explained/ta-p/206632
Correct answer is 100% A. Check Study Guide p350
During web Filtering Inspection, Fortigates first check the Static Url Filter list, then the fortiguard categories, and then the content filter list. So even if the static url is allowing the site, it will be blocked and dropped by the fortiguard categories action.
The correct answer is A. Explanation:
https://community.fortinet.com/t5/FortiGate/Technical-Note-List-of-web-filtering-steps-and-their-order-of/ta-p/197439?cmd=displayKC&docType=kc&externalId=11158
Web filters are applied in this specific order:
1 URL Filter
2 FortiGuard Web Filter (also called Category Block)
3 Content Filter (Web Content Filter)
4 Script Filter (filters for Java applets, ActiveX controls and cookies, CLI config only)
5 Antivirus scanning
The URL filter list is processed in order from top to bottom. An exempt match stops all further checking including AV scanning. An allow match exits the URL filter list and checks the other web filters.
In this case, the action in the URL Filter is "allow" therefore the FortiGate checks the other web filters. In this case, the next web filter is the FortiGuard Category Based Filter, which in this case is set to block.
Therefore traffic is blocked based on the FortiGuard Category Based Filter.
A
the order is
URL filter
2. FortiGuard Web Filtering
3. Web content filter
4. Web script filter
5. Antivirus scanning
But to be allowed without matching any other critiria it should be exempt and not allowed
A: Allow
The traffic is passed to the remaining FortiGuard web filters, web content filters, web script filters, antivirus proxy operations, and DLP proxy operations. If the URL does not appear in the URL list, the traffic is permitted.
Web Filtering inspection is performed in the following order:
1 - URL filter
2 - FortiGuard Web Filter (FortiGuard Category Based Filter)
3 - Web Content Filter
4 - Advanced Filter Options
In this case: URL Filter - allow. But in the second step, the blocks by the Category Based Filter.
Answer A is correct.
Reason: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Difference-between-action-Allow-and-Exempt-in/ta-p/231334
In the URL Filter (which is checked FIRST) dropbox.com is ONLY allowed which prompts Fortigate to check fruther in the UTM (next ist FortiGuard Web Filtering which BLOCKS file sharing).
In Order for D to be correct, the URL Filter would need to set dropbox.com on "exempt" (which leads the fortigate to stop checking and allow the traffic at once).
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
tururu1496
Highly Voted 1 year, 10 months agojavim
1 year, 1 month agoklapek
1 year, 10 months agojavim
1 year, 1 month agotururu1496
1 year, 10 months agotururu1496
1 year, 10 months agoRudi36
Highly Voted 1 year, 7 months agoGCISystemIntegrator
Most Recent 5 months, 1 week agocbu_ch
9 months, 2 weeks agoFortiNoob
10 months, 1 week agoLAFNELL
10 months, 2 weeks agomikerss
11 months agomordechayd
11 months, 1 week agoricjscarvalho
1 year agored74
1 year agoPoBratsky
1 year agofy64
1 year, 1 month agoolimmu
1 year, 1 month agoKocX
1 year, 1 month agojdubyah_
1 year, 1 month agoRottcrown95
1 year, 1 month agoscheuri
1 year, 1 month ago