Chapter 3 System Administration : Advanced concepts : Blocking HTTP access by IP

Blocking HTTP access by IP
To block a web site using the IP, create a URL filter entry, using the additional information below. Note that this is only effective with HTTP or FortiGate units running Deep Inspection.
You need to create two URL filter entries. The first filter only allowing a text string containing two or more sets of text separated by a period. This is to match the various domain possibilities for web sites, for example:
The second filter blocks any IP address lookup.
To add the URL filter entries
Go to UTM Profiles > Web Filter > URL Filter.
Select Create New to add a filter group, give it a name and select OK.
Select Create New for a new filter.
Enter the URL of ^([a-z0-9-]+\.){1,}[a-z]+
Set the Type to Regex.
Set the Action to Allow.
Select Create New.
Enter the URL of [0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}
Set the Type to Regex.
Set the Action to Block.
Position these at the end of the URL filter list so that any exemptions or blocks before that are still effective.
Both of these filter entries are required. If you only enter the second one, the FortiGate unit will also catch a URL lookup as they both behave in a similar fashion after the URL is resolved to an IP. The first entry is needed to break out of the URL filter and allow the web site before it does the second check if they entered text.

FortiOS Handbook, FortiOS 4.0 MR3
01-431-99686-20110916 · 16 September 2011
© 2011 Fortinet, Inc. All rights reserved.
Latest documentation:
Contact us: