Skip to main content
coregonus
New Member
February 26, 2025
Question

FortiClient Webfilter blocks legitimate webtraffic because "unknown"

  • February 26, 2025
  • 5 replies
  • 2557 views

We have this issue, where some clients are getting a lot of legitimate URLs blocked, because they seem to be "unknown", although they are not unknown. These are common sites from Microsoft for example. This happens with remote clients that use FortiClient Webfiltering: blocked traffic log in Forticlientblocked traffic log in ForticlientWord security warning because of FortiClient certificateWord security warning because of FortiClient certificateFortiClient certificateFortiClient certificate

Now the users get certificate error messages in Word for example, because Forticlient blocks the URL and provides its own certificate.
Why does this happen? Client has proper internet access, DNS is working accordingly. Problem happens with FortiClient 7.2.5 and also 7.2.8. Any ideas?

5 replies

Stephen_G
Moderator
Moderator
March 2, 2025

Hello,

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Stephen_G - Fortinet Community Team
Stephen_G
Moderator
Moderator
March 4, 2025

Hi,

 

Sorry, we're still trying to get you an answer or reply. In the meantime, if anyone viewing this topic has a possible answer, your input is welcomed.

Stephen_G - Fortinet Community Team
coregonus
coregonusAuthor
New Member
March 6, 2025

Hello Stephen

 

Many thanks for your response.

If you need any logs or something similar, please let me know.

I assume, for some reason, FortiClient cannot reach FortiGuard services, but I dont know good techniques to test that properly. The only thing I have tried is reaching fortiguard.net and it was at least possible to resolve this FQDN to IP. Do you have any suggestions on what I could try to troubleshoot that properly?

Thanks!

Stephen_G
Moderator
Moderator
March 7, 2025

Sorry this is taking a while, coregonus. I take it you have consulted this article/doc? https://community.fortinet.com/t5/FortiClient/Technical-Tip-FortiClient-Web-Filtering-rating/ta-p/219265

Stephen_G - Fortinet Community Team
coregonus
coregonusAuthor
New Member
March 10, 2025

Hello Stephen, thanks for the link above, where its pointed out that fgd1.fortigate.com specifically needs to be reachable. The next time one of the users will report that issue, I'm going to check, if this URL fgd1.fortigate.com is reachable. What I often miss in FortiClient is some sort of health status page, where I could shortly check basics like:

  • Is this FortiGuard service reachable and correctly connected?

This would make life much easier, at the moment it is just guessing. Maybe the computer itself can ping FortiGuard services, but FortiClient maybe still cannot correctly connect to it. In these situations I'm almost completely blind. Then I need to export FortiClient debug log, where most of the information is not clear to me what it means. If I could raise a feature request, it would be for sure this one: health status for FortiClient :) would save you a lot of work too, if clients would not raise incident tickets for basic problems. Thanks!