Troubleshooting Tip: SFTP connections are failing whenever the Web Filter is enabled
| Description | This article describes why SFTP connections may fail when the Web Filter is enabled, even though these connections are not being specifically blocked by the firewall. |
| Scope | FortiOS 7.4.8, 7.6.3. |
| Solution | When the 'Enforce 'Safe Search' on Google, Yahoo!, Bing, Yandex' feature is enabled in the Web Filter, this may cause SFTP connections to fail unexpectedly.
This is due to a known issue being tracked under #1191728. If there are no logs that show the FortiGate blocking this session and this option is enabled, it is possible this is the issue. This should also only occur when the policy is in Flow mode.
If Safe Search needs to stay enabled, switch the policy to Proxy-based mode as a workaround, or create a new policy with the SFTP server as the destination with no Web Filter enabled.
It is possible to confirm this by taking an IPS debug filtered to the SFTP traffic. See Troubleshooting Tip: IPS engine new debug commands. The following is some example output of the issue occurring. It is possible to see the FortiGate tear down the session after it is established, usually with 'reason 3' in the output:
|
