Skip to main content
Arif69
Staff
Staff
November 25, 2025

Troubleshooting Tip: Unable to enable 'antispam-force-off' and 'webfilter-force-off' in FortiManager device database

  • November 25, 2025
  • 0 replies
  • 188 views
Description This article describes how to enable the 'antispam-force-off' and 'webfilter-force-off' FortiGuard settings from the FortiManager device database to FortiGate.
Scope FortiManager.
Solution

Currently, the settings for 'antispam-force-off' and 'webfilter-force-off' of FortiGuard settings in local FortiGate are disabled:

 

chrome_qEARg0qeiB.png

 

To enable the settings from FortiManager, navigate to Device Manager -> Device & Groups -> FortiGate -> CLI Configurations -> System -> FortiGuard. Enable the 'antispam-force-off' and 'webfilter-force-off'.

 

chrome_HX6amqz8HY.png

 chrome_DPZWDZoaJD.png

 

However, when trying to install the changes to the FortiGate, there are no changes to be pushed:

 

chrome_Dkd8MYtlOW.png

 

After the installation is finished, somehow the 'antispam-force-off' and 'webfilter-force-off' settings are automatically disabled:

 

chrome_Ufge6Ya2yY.png

 

chrome_SplvdVAGyA.png

 

After further investigation, it was found that the FortiGate is assigned a system template with the 'FortiGuard' setting enabled:

 

siLC7SZCGz.png

 

To solve this issue, there are two ways:

  1. Disable the 'FortiGuard' setting.
  2. Or unassign the template from the FortiGate.

 

Next, navigate to Device Manager -> Device & Groups -> FortiGate -> CLI Configurations -> System -> FortiGuard to enable the 'antispam-force-off' and 'webfilter-force-off' again.

 

After that, it can be seen that FortiManager is now able to push the 'antispam-force-off' and 'webfilter-force-off' settings:

 

chrome_NRMfR3oxrt.png