Fortinet black logo

Handbook

Configuring an L2 exception list

Configuring an L2 exception list

In some jurisdictions, SSL interception and decryption is disfavored for some types of websites or disallowed entirely. You use the L2 Exception List configuration to define such destinations. You can leverage FortiGuard web filter categories, and you can configure a list of additional destinations.

Before you begin:

  • You must have created a Web Filter Profile configuration that includes the web categories to exclude from SSL decryption.
  • You must have hostname or IP address details on additional destinations you want to exclude from SSL decryption.
  • You must have Read-Write permission for Load Balance settings.

After you have created an L2 exception list configuration object, you can select it in a Layer 2 virtual server configuration.

To configure an exception list:
  1. Go to Server Load Balance > SSL-FP Resources.
  2. Click the L2 Exception List tab.
  3. Click Create New to display the configuration editor.
  4. Complete the configuration as described in L2 exception list configuration.
  5. Save the configuration.

L2 exception list configuration

Settings Guidelines

Name

Configuration name. Valid characters are A-Z, a-z, 0-9, _, and -. No spaces. You reference this name in the profile configuration.

Note: After you initially save the configuration, you cannot edit the name.

Description

A string to describe the purpose of the configuration, to help you and other administrators more easily identify its use.

Web Filter Profile

Select a Web Filter Profile configuration.

Member

Type

How you want to define the exception:

  • Host
  • IP

Host Pattern

Specify a wildcard pattern, such as *.example.com.

IP/Netmask

Specify the IP address and CIDR-formatted subnet mask, separated by a forward slash, such as 192.0.2.0/24.

Note:

  • Dotted quad formatted subnet masks are not accepted.
  • IPv6 addresses are not supported.

Configuring an L2 exception list

In some jurisdictions, SSL interception and decryption is disfavored for some types of websites or disallowed entirely. You use the L2 Exception List configuration to define such destinations. You can leverage FortiGuard web filter categories, and you can configure a list of additional destinations.

Before you begin:

  • You must have created a Web Filter Profile configuration that includes the web categories to exclude from SSL decryption.
  • You must have hostname or IP address details on additional destinations you want to exclude from SSL decryption.
  • You must have Read-Write permission for Load Balance settings.

After you have created an L2 exception list configuration object, you can select it in a Layer 2 virtual server configuration.

To configure an exception list:
  1. Go to Server Load Balance > SSL-FP Resources.
  2. Click the L2 Exception List tab.
  3. Click Create New to display the configuration editor.
  4. Complete the configuration as described in L2 exception list configuration.
  5. Save the configuration.

L2 exception list configuration

Settings Guidelines

Name

Configuration name. Valid characters are A-Z, a-z, 0-9, _, and -. No spaces. You reference this name in the profile configuration.

Note: After you initially save the configuration, you cannot edit the name.

Description

A string to describe the purpose of the configuration, to help you and other administrators more easily identify its use.

Web Filter Profile

Select a Web Filter Profile configuration.

Member

Type

How you want to define the exception:

  • Host
  • IP

Host Pattern

Specify a wildcard pattern, such as *.example.com.

IP/Netmask

Specify the IP address and CIDR-formatted subnet mask, separated by a forward slash, such as 192.0.2.0/24.

Note:

  • Dotted quad formatted subnet masks are not accepted.
  • IPv6 addresses are not supported.