Skip to main content
yeowkm99
New Member
November 17, 2021
Question

Internet traffic blocked by policy violation

  • November 17, 2021
  • 10 replies
  • 16867 views

Our internet users encounter issue whereby Internet services like office 365, access to google etc is blocked suddenly by policy violation.

the way to bypass it is to launch browser using administrator rights 

10 replies

network360_2021
New Member
November 17, 2021

enable Implicit policy logging and check the reason , did you using ISDB based policy .

if you are using ISDB then some time office365 ip missing .

first you have to check your DNS server is resolving IP for the office365 and we have to check office365 ip address in ISDB for steps please check below kb

https://kb.fortinet.com/kb/documentLink.do?externalID=FD47288

 

 

yeowkm99
yeowkm99Author
New Member
November 17, 2021
Debbie_FTNT
Staff & Editor
Staff & Editor
November 17, 2021

Hey yeowkm99,

 

the page you linked is just an explanation that traffic logged as deny may show with the referenced threat ID.
This does NOT explain why traffic is blocked in the first place, which is what I think you're after?

Do you have any kind of authentication setup on your FortiGate?
Given that you mentioned running the browser as admin is a functioning workaround, that sounds to me a little like there might be something going on with authentication.
In particular, running the browser as admin could trigger a login event (that might be picked up through FSSO), or would cause NTLM/Kerberos to detect the admin user.

If the FortiGate for some reason lost the regular user authentication information (timeout maybe?) that could cause traffic to no  longer match (being denied for policy violation instead), and running the browser as admin, treated as a new login, could cause the traffic to match again.
I would suggest you have a look at traffic logs for the affected source IP before and after running the browser as admin, and check what differences there are - for the allowed traffic, does a username show in the logs, for example?
You might want to enable logging all sessions in the policy, to ensure that allowed traffic is captured properly.

Cheers!

yeowkm99
yeowkm99Author
New Member
November 18, 2021

encountered the same issue after i come to office in the morning.

seems like there is a need for AD authentication. 

Cannot show the logs as i don't have permission to upload images.

network360_2021
New Member
November 18, 2021

please check the authentication of the computer - ip address .

goto FSSO collector --> Show logon Users ---> and search for the IP address before entering Admin user . here you  can see FSSO detail for this endpoint/laptop. same step repeat after enter Admin user name and password and check the FSSO detail .

here we can pinpoint issue is related SSO .

if you don't have access to collector agent server we can verify from the Fortigate

goto cli --> diagnose debug authd fsso filter source x.x.x.x (ip address)

diagnose debug authd fsso list

or you can check in the GUI for the users

 

 

seadave
New Member
November 18, 2021

Long shot, but you might check to see if your DCs were updated last night.  This week's updates caused some DC auth issues.

 

https://www.bleepingcomputer.com/news/microsoft/windows-kerberos-authentication-breaks-due-to-security-updates/

 

If you have FSSO in place, perhaps it isn't able to properly communicate with your DCs and that is why only Administrator is working?  That kind of makes sense if you are launching the browser with Domain Admin rights (actually this is a nightmare, never do this!), but if you are speaking about local administrator rights then perhaps a dead end.  You can copy your policy that uses authentication and remove that feature, place it above your current policy and disable the one that isn't working until you are able to better review your Fortigate and or FSSO logs.  I'd open a case with the TAC, they should be able to help.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!