Skip to Content

How Web Content Filtering Bypassing Block Action on Google Search Due to SSL Full Inspection

This article describes how the SSL Inspection profile may be exempting Google search causing web content filtering to be bypassing the banned word instead of blocking.

Scope

FortiGate.

Solution

The reason why web content filtering may be allowed while searching from Google is because the SSL Inspection profile is used in the firewall policy exempts Google domains from being inspected.

Navigate to Policy & Objects > Firewall Policies. Locate the firewall policy that has been configured to use the web filter profile.

Navigate to Policy & Objects, Firewall Policies. Locate the firewall policy that has been configured to use the web filter profile.

Edit the SSL Inspection profile being used, in this example, ‘custom-deep-inspection’.

Review the Exempt from SSL Inspection and make sure Search Engines and Portals are removed from the web categories and google FQDN from the addresses.

Review the Exempt from SSL Inspection and make sure Search Engines and Portals are removed from the web categories and google FQDN from the addresses.

When testing and trying to search for the banned word ‘Reddit’ on Google search, it has been blocked by the content filter setup:

When testing and trying to search for the banned word 'Reddit' on Google search, it has been blocked by the content filter setup.