FortiGate Multi-Threat Security Systems I



Similar documents
FortiGate Multi-Threat Security Systems I Administration, Content Inspection and SSL VPN Course #201

Fortinet Certified Network Security Administrator

HA OVERVIEW. FortiGate FortiOS v3.0 MR5.

Fortinet Network Security NSE4 test questions and answers:

FortiOS Handbook WAN Optimization, Web Cache, Explicit Proxy, and WCCP for FortiOS 5.0

SERVICE DESCRIPTION Web Proxy

FortiGate High Availability Overview Technical Note

WAN Optimization, Web Cache, Explicit Proxy, and WCCP. FortiOS Handbook v3 for FortiOS 4.0 MR3

Burst Technology. bt-webfilter User Guide

Hosting more than one FortiOS instance on. VLANs. 1. Network topology

FortiOS Handbook - WAN Optimization, Web Cache, Explicit Proxy, and WCCP VERSION 5.2.4

QUESTION: 1 Which of the following are valid authentication user group types on a FortiGate unit? (Select all that apply.)

Analyzing your network traffic using a onearmed

Reverse Proxy Guide. Version 2.0 April 2016

Firewall. FortiOS Handbook v3 for FortiOS 4.0 MR3

CA Nimsoft Monitor. Probe Guide for URL Endpoint Response Monitoring. url_response v4.1 series

HUAWEI OceanStor Load Balancing Technical White Paper. Issue 01. Date HUAWEI TECHNOLOGIES CO., LTD.

FortiOS Handbook - Load Balancing VERSION 5.2.2

ProxySG TechBrief Implementing a Reverse Proxy

Controlling Risk, Conserving Bandwidth, and Monitoring Productivity with Websense Web Security and Websense Content Gateway

FortiOS Handbook - Security Profiles VERSION 5.4.0

FortiOS Handbook Load Balancing for FortiOS 5.0

HTTPS HTTP. ProxySG Web Server. Client. ProxySG TechBrief Reverse Proxy with SSL. 1 Technical Brief

Deploying the Barracuda Load Balancer with Office Communications Server 2007 R2. Office Communications Server Overview.

McAfee Web Gateway 7.4.1

Load Balancing. FortiOS Handbook v3 for FortiOS 4.0 MR3

Troubleshooting. FortiOS Handbook v3 for FortiOS 4.0 MR3

Integrated SSL Scanning

FortiOS Handbook Security Profiles for FortiOS 5.0

FortiOS Handbook - Hardening your FortiGate VERSION 5.2.3

ProxySG TechBrief Enabling Transparent Authentication

Reverse Proxy with SSL - ProxySG Technical Brief

Barracuda Web Filter Demo Guide Version 3.3 GETTING STARTED

How To Plan A Desktop Workspace Infrastructure

FortiOS Handbook What s New for FortiOS 5.0

Application Control and URL Filtering

How To Configure The Fortigate Cluster Protocol In A Cluster Of Three (Fcfc) On A Microsoft Ipo (For A Powerpoint) On An Ipo 2.5 (For An Ipos 2.2.5)

Configuration Example

Application Note. Configuring McAfee Firewall Enterprise for McAfee Web Protection Service

REQUIREMENTS AND INSTALLATION OF THE NEFSIS DEDICATED SERVER

How To Set Up The Barclaycard Epdq Cardholder Payment Interface (Cpi) On Papercut (Barclay Card) On A Microsoft Card (For A Credit Card) With A Creditcard (For An Account)

NETASQ MIGRATING FROM V8 TO V9

FortiGate IPS Guide. Intrusion Prevention System Guide. Version November

FortiGuard Web Content Filtering versus Websense March 2005

How To Authenticate An Ssl Vpn With Libap On A Safeprocess On A Libp Server On A Fortigate On A Pc Or Ipad On A Ipad Or Ipa On A Macbook Or Ipod On A Network

Managing a FortiSwitch unit with a FortiGate Administration Guide

Please report errors or omissions in this or any Fortinet technical document to

Supported Upgrade Paths for FortiOS Firmware VERSION

Controlling which applications can access network resources and the Internet

FortiMail Filtering Course 221-v2.2 Course Overview

FortiMail Filtering. Course for FortiMail v4.0. Course Overview

Using a custom certificate for SSL inspection

February Considerations When Choosing a Secure Web Gateway

DEPLOYMENT GUIDE Version 2.1. Deploying F5 with Microsoft SharePoint 2010

DEPLOYMENT GUIDE Version 1.1. DNS Traffic Management using the BIG-IP Local Traffic Manager

Configuring PA Firewalls for a Layer 3 Deployment

v7.8.2 Release Notes for Websense Content Gateway

fåíéêåéí=péêîéê=^çãáåáëíê~íçêûë=dìáçé

IIS SECURE ACCESS FILTER 1.3

(91) FortiOS 5.2

Fireware XTM Traffic Management

PaperCut Payment Gateway Module - PayPal Payflow Link - Quick Start Guide

Internet Filtering Appliance. User s Guide VERSION 1.2

H3C Firewall and UTM Devices DNS and NAT Configuration Examples (Comware V5)

Content Filtering Client Policy & Reporting Administrator s Guide

FortiOS Handbook - FortiView VERSION 5.2.3

PRODUCT VERSION: LYNC SERVER 2010, LYNC SERVER 2013, WINDOWS SERVER 2008

GoToMyPC Corporate Advanced Firewall Support Features

Collax Web Security. Howto. This howto describes the setup of a Web proxy server as Web content filter.

1 You will need the following items to get started:

Understanding Slow Start

NEFSIS DEDICATED SERVER

Web Application Firewall

Networking and High Availability

A Guide to New Features in Propalms OneGate 4.0

Endpoint web control overview guide. Sophos Web Appliance Sophos Enterprise Console Sophos Endpoint Security and Control

z/os V1R11 Communications Server system management and monitoring

FortiOS Handbook - Security Profiles VERSION 5.2.4

Quick Note 026. Using the firewall of a Digi TransPort to redirect HTTP Traffic to a proxy server. Digi International Technical Support December 2011

Sophos for Microsoft SharePoint startup guide

Configuration Information

SuperLumin Nemesis. Administration Guide. February 2011

Deployment Guide Microsoft IIS 7.0

LifeSize UVC Access Deployment Guide

Content Inspection Features

v Installation Guide for Websense Enterprise v Embedded on Cisco Content Engine with ACNS v.5.4

Lab Configuring Access Policies and DMZ Settings

SSL EXPLAINED SSL EXPLAINED

Mobile Device Management Version 8. Last updated:

PaperCut Payment Gateway Module - PayPal Payflow Link - Quick Start Guide

FortiManager - Secure DNS Guide VERSION 5.4.1

Healthstone Monitoring System

Websense Web Security Gateway: What to do when a Web site does not load as expected

McAfee Web Gateway Administration Intel Security Education Services Administration Course Training

FortiWeb 5.0, Web Application Firewall Course #251

PAN-OS Syslog Integration

Securing Networks with PIX and ASA

Mobile Configuration Profiles for ios Devices Technical Note

Transcription:

FortiGate Multi-Threat Security Systems I Module 9: Web Filtering 2013 Fortinet Inc. All rights reserved. The information contained herein is subject to change without notice. No part of this publication including text, examples, diagrams 1 or illustrations may be reproduced, transmitted, or translated in any form or by any means, electronic, mechanical, manual, optical or otherwise, for any purpose, without prior written permission of Fortinet Inc. 01-50003-0201-20131018-D

Module Objectives By the end of this module participants will be able to:» Identify the web filtering mechanisms used on the FortiGate device» Create web content and URL filters» Configure FortiGuard Web Filtering» Configure FortiGuard Web Filtering exemptions and rating overrides» Define firewall policies using web filter profiles» Explain the differences between various web filter modes 2

Web Filtering Means of controlling the web content that a user is able to view» Preserve employee productivity» Prevent network congestion where valuable bandwidth is used for non-business purposes» Prevent loss or exposure of confidential information» Decrease exposure to web-based threats» Limit legal liability when employees access or download inappropriate or offensive material» Prevent copyright infringement caused by employees downloading or distributing copyrighted materials» Prevent children from viewing inappropriate material 3

Proxy-Based Web Filtering Proxy based solution that communicates between client and server Inspects full URL Allows for customizable block pages to display when sites are prevented Most resource intensive option Lowest throughput Has the Most options available in Advanced section 4

Proxy-Based Web Filtering Select inspection mode in web filter profile 5

Flow-Based Web Filtering Non-proxy solution that uses IPS engine to perform inspection High throughput Inspects full URL FortiGuard Web Filtering override will not apply when flow-based inspection is enabled Only a few Advanced options available Not as flexible as proxy-based» Allow, Monitor, Block ONLY» Warn and Authenticate not possible» Overrides not possible 6

Flow-Based Web Filtering Select inspection mode in web filter profile 7

DNS-Based Web Filtering DNS-proxy solution that uses DNS queries to decide access DNS queries redirected to FortiGuard SDNS server Very lightweight SSL inspection never required Cannot inspect URL, only hostname (DNS) Supports URL Filtering and FortiGuard Category only No individual block pages, can redirect to a portal Web site access by IP means no DNS lookup 8

DNS-Based Web Filtering Select inspection mode in web filter profile 9

When Does Filtering Activate? www.acme.com DNS Request! TCP 3-Way Handshake DNS Response HTTP GET! HTTP 200 10

HTTP Inspection Order EXEMPT (from ALL further inspection) Block Page URL Exempt Web URL Filter Allow Block FortiGuard Filter Block Allow Block Page Block Page Block Advanced Filter Allow Content Filter Allow Block Block Page Block Virus Scan Allow Display Page Block Page 11

Types of Web Filtering Proxy-Based» Highly secure» Traffic is cached Flow-Based» High throughput» No caching» Not as secure DNS-Based» Very lightweight» Hostname filtering only» No advanced options, URL and FortiGuard only 12

Web Content Filtering Allow or block web pages containing specific words or patterns» Wildcards or regular expressions used to define patterns Scores for matched patterns are added» If greater than threshold, FortiGate unit performs configured action» If pattern appears multiple times on web page, score is only counted once www.acme.com Create Pattern list in the CLI Drugs Score=10 Pharmacy Score=5 Prescription Score=5 Threshold=18 10 +5 +5 =20 Block or Exempt 13

Web URL Filtering Control web access by allowing or blocking URLs» Text, wildcards or regular expressions can be used to define the URL patterns» If no URL match on list, go on to next enabled check Possible web URL filter actions are:» Allow» Block» Monitor» Exempt 14

Web URL Filtering URL: www.mypage.com/index.html URL Filter list www.example.com www.abc.com www.mypage.com/index.html Block Allow Monitor Exempt www.mypage.com 15

Forcing Safe Search Safe Search is used by search sites to prevent explicit web sites and images from appearing in search results FortiGate unit rewrites the search URL to include the required codes to enable Safe Search» Supported for Google, Bing, Yahoo! And Yandex» Does NOT force strict safe search Youtube EDU available» Instructions for Youtube will include value to enter on FortiGate unit 16

FortiGuard Category Filter URL: www.mypage.com Categories Allow Block Monitor Warning Authenticate www.mypage.com 17

FortiGuard Category Filter The FortiGate unit accesses the FortiGuard Distribution Server to determine the category of a requested page» Action is taken based on selection in web filtering profile Web filter rating determined by:» Human rater» Text analysis» Exploitation of web structure Description of Categories can be found on FortiGuard website http://www.fortiguard.com/static/webfiltering.html 18

FortiGuard Category Filter Split into multiple categories and sub-categories Layout will switch periodically as the Internet changes New categories and sub-categories are released and compatible with updated firmware» Older firmware has new values mapped to existing categories 19

FortiGuard Caching Most web sites are visited over and over again» FortiGate unit can remember what the response was Caching improves performance by reducing FortiGate unit requests to FortiGuard servers» Cache checked before sending request to FortiGuard server» TTL settings controls the number of seconds query results are cached Small amount of FortiGate unit system memory dedicated to the cache» Default is 2% used for cache, can be increased to 15% from CLI Port 53 used for FortiGuard communications» Alternate port number of 8888 can used KB Article IDs: 11779, FD32121, FD30088 20

FortiGuard Usage Quotas Games Quota Category: Games Games Quota Games Quota Quotas allow access to specific categories for a specific length of time (calculated separately for each quota configured) If authentication is enabled, quota is automatically based on the user, otherwise IP is used Can only apply to categories with actions: Monitor, Warn or Authenticate 21

Rating Submissions Requests for rating of a web site, or to have a web site s rating re-evaluated can be submitted by accessing:» http://www.fortiguard.com/ip_rep.php 22

Rating Override Rating override Category: General Organizations www.acme.com Sub-Category: Information and Computer Security 23

Rating Override Can override the rating applied to a hostname by FortiGuard Subscription Services» Hostname reassigned to a completely different category and uses that action Override applies to FortiGate unit only» Changes not submitted to FortiGuard Subscription Services Hostnames only» google.com» www.google.com» www.google.com/index.html 24

Local Categories Rename and deletion of sub-categories only in CLI config webfilter ftgd-local-cat delete <cat_name> rename <cat_name> to <cat_name> 25

Warning Action Action = Warning (right click in the GUI) Web Filtering Warning Page 26

Authenticate Action Marketing www.hackthissite.org 27

Web Filter Profiles Web filtering, FortiGuard web filtering and Advanced Filter options enabled through web filtering profiles Profile in turn applied to firewall policy» Any traffic being examined by the policy will have the web filtering operations applied to it 28

Labs Lab 1: Web Filtering» Ex 1: FortiGuard Web Filtering 29

30 Classroom Lab Topology