FortiClient Manager : Configuring FortiClient agent settings : Configuring web filter options on a FortiClient agent
 
Configuring web filter options on a FortiClient agent
You can enable Web Filtering that uses the FortiGuard Web Filtering service to help you control web access by URL. For FortiClient agents and groups, web filtering profiles determine which categories of URLs are blocked and which specific URLs are always blocked or always allowed. See “Viewing and editing web filter profiles”.
FortiGuard web filtering is a managed Web Filtering solution provided by Fortinet. FortiGuard-Web sorts hundreds of millions of web pages into a wide range of categories users can allow, block, or monitor.
The FortiManager unit can act as the local FortiGuard web filtering service center, overriding the default FortiGuard servers. If you have a large number of FortiClient agents, using this feature speeds up the installation of the web filtering settings.
You can specify a replacement web page for the FortiClient agent to display to users when a URL is blocked because of its category or because it is in the block site list. See “To configure custom web filter block web pages:”.
To configure web filter options:
1. In the FortiClient Manager, select Client/Group > Client > Managed Client in the navigation pane.
2. In the All Managed Clients list, select the FortiClient agent you want to configure from the Host Name column.
3. From the FortiClient menu, select Web Filter > Option > Basic Setting.
4. Configure the following settings and select Apply.
Override
The FortiClient agent’s configuration includes those inherited from the group to which the computer belongs.
Selecting override allows you to modify the inherited FortiGuard server on this FortiClient agent. Deselecting override means that you want to use the FortiGuard server inherited from the group to which the computer belongs.
Enable Web Filter
Select to enable web filtering.
Default behavior for unrated URLs
Select whether to allow or block URLs that are not known to FortiGuard Web. The default is Allow.
Log all visited URLs
Log all visited URLs to FortiAnalyzer or syslog server
Disable IP Address Rating
Filter by domain rating only. Sometimes filtering by IP address can produce false positives.
Override Default Web Filter Server
Select to get the web filter settings from the FortiManager unit:
Enter the unit’s IP address.
Enter the unit’s port number.
To configure custom web filter block web pages:
 
If the web filter block page is customized, it MUST be written in UTF-8. Because the URL rating category is in UTF-8, the character set cannot be mixed in one page.

Use the following line to help the web browser select the correct code page to display.
<meta http-equiv='content-type' content='text/html; charset=UTF-8'>
1. In the FortiClient Manager, select Client/Group > Client > Managed Client in the navigation pane.
2. In the All Managed Clients list, select the FortiClient agent you want to configure from the Host Name column.
3. From the FortiClient menu, select Web Filter > Option > Custom Block Page.
4. Select Override to override the group settings for this FortiClient agent.
5. Select Custom for the page you want to customize and then do one of the following:
Enter the HTML text into the text box.
or
Select Browse, find the HTML file of the custom page content and select Upload.
6. Optionally, select Preview to view the custom page.
7. Select Apply.