Skip to main content
esa12
Explorer
February 20, 2025
Question

Accessing url blocked by fortigate action : server-rst

  • February 20, 2025
  • 10 replies
  • 15087 views

I have an issue when accessing url by ip address using https. Why does the firewall block web access and how do I solve it? all i can see in the log is:

 

ssl block.jpg

10 replies

AEK
SuperUser
SuperUser
February 20, 2025

Server Reset is an action performed from server side, not by firewall.

AEK
ilias87
Explorer
April 7, 2025

Same issue here,  any idea how to solve it?

AEK
SuperUser
SuperUser
April 7, 2025

Server-rst event most probably means the issue is from server side.

Check the related logs on the server, typically the logs of the application that you trying to access.

AEK
ilias87
Explorer
April 7, 2025

It is quite weird because it appeared after an upgrade to version 7.2.11.

Device tries to access its gateway ( Fortigate is in the middle with a virtual wire pair , in bridge mode) and this issue appeared. It tries to access it in https directly to an ip address as esa12 mentioned. I whitelisted ssl application with id 15895 but stil traffic is being blocked. Anything else (that passes through the same gateway) operates normally. 

AEK
SuperUser
SuperUser
April 7, 2025

Hi Ilias

Did you say "traffic is being blocked"? Or is it "server-rst"? If the traffic is being blocked then I guess the traffic is not matched by the expected rule, right?

AEK
ilias87
Explorer
April 9, 2025

Hi AEK , I am using virtual wire pair policy for the whole local interface (Fortigate in transparent mode) and the local devices cannot access their gateway in https. (etc https://192.168.100.1). My ssl inspection policy was in "read-only ssl inspection" mode and when i change it temporary in "no inspection" , page is accessible again. Please note that this happened after an upgrade from 7.2.9 to 7.2.11 version. So clearly Fortigate doesn't like the cerficate of this local page , but i cannot add an exception for ip address  in "read-only ssl inspection " mode. The log message is correct "server-rst". Thanks for assistance!

AEK
SuperUser
SuperUser
April 9, 2025

Hi ilias

If the SSL inspection profile is blocking the traffic that means FGT doesn't like the certificate as you said.

In that case you should find in the FGT SSL logs why the certificate has been blocked, and then you can tune the SSL inspection profile accordingly.

AEK
Dhruvin_patel
Staff
Staff
April 9, 2025

Greetings!

 

The 'server-rst' action in a log indicates that the server has reset the connection; this does not mean that the FortiGate is blocking the connection.

 

There are a few possible reasons that you would get a "server-rst" action, e.g. the client did not send any info for a while for some reasons and the server decides to terminate the session, or if the client sends a FIN and the server may decide to send a RST instead of a FIN.

 

Regards!

zen
New Member
January 30, 2026

server-rst in this context was sent by the firewall itself, as mentioned above, most likely due to UTM not liking the cert on the server end 
some reading click 

On analyzer this looks like this 

Event Actionblocked
Event ID62305
Event MessageSSL connection is blocked due to unable to retrieve server's certificate
Event Profilecertificate-inspection
Event Severitywarning
Event Sub Typessl
Event Typeutm
 
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!