User Group User
FortiGate Version 4.0 MR1 Administration Guide
672 01-410-89802-20090903
http://docs.fortinet.com/ • Feedback
Configuring FortiGuard Web filtering override options
FortiGuard Web Filtering is a managed web filtering solution that sorts hundreds of
millions of web pages into a wide range of categories that users can allow, block, or
monitor. The FortiGate unit accesses the nearest FortiGuard Web Filtering Service Point
to determine the category of a requested web page and then follows the firewall policy
configured for the user or interface. The FortiGuard Web Filtering Override option is
available only if the user group is Firewall or Directory Service.
To configure FortiGuard Web Filtering Override, go to User > User Group and select the
Edit icon for a Firewall or Directory Service user group. Select the Expand Arrow beside
FortiGuard Web Filtering Override, and enter or select the following information:
Figure 419: FortiGuard Web Filtering Override configuration
Allow to create FortiGuard
Web Filtering overrides
Select to allow members of this group to request an override
on the FortiGuard Web Filtering Block page. The firewall
protection profile governing the connection must have
FortiGuard overrides enabled.
The protection profile may have more than one user group as
an override group. Members of an override group can
authenticate on the FortiGuard Web Filter Block Override
page to access the blocked site.
For more information, see “FortiGuard - Web Filter” on
page 559.
Override Scope The override can apply to just the user who requested the
override, or include others. Select one of the following from
the list:
User Only the user.
User Group The user group to which the user belongs.
IP Any user at the user’s IP address.
Profile Any user with the specified protection profile of the user
group.
Ask Authenticating user, who chooses the override scope.
User Only the user.
Override Type Select from the list to allow access to:
Directory Only the lowest level directory in the URL.