URL Scan Flow
After a URL is received from an input source, it goes through the following steps before a verdict is reached. If a verdict can be reached at any step, the scan will stop.
- Static Scan
In this step, the URL is checked against the user uploaded White/Black list and the Overridden Verdicts list.
- Sandboxing Scan
If WEBLink is associated with a VM type as defined in the Scan Profile page > VM Association tab, the URL will be scanned inside a clone of that VM type. If the URL type is enabled with the
sandboxing pre-filtering
command, only URLs whose webfiltering category is UNRATED will be scanned inside a VM. For more information, please refer to the FortiSandbox CLI Guide, for thesandboxing-prefiltering
command.
During the Static Scan step, URLs will be checked against the user uploaded white list and black list in this order, and rated as Clean or Malicious respectively: URL REGEX black list > URL black list > Domain black list > URL REGEX white list > URL white List > Domain white list. For example, if users enter |