Skip to main content
YASH1994
New Member
June 5, 2018
Solved

Web filter is not working properly in forti os 5.6?

  • June 5, 2018
  • 2 replies
  • 31385 views

This is a newly configured Firewall. we try to enable the web filter in that. LAN pc's connect to the internet before enable the web filter. But after enable the web filter it's not connect to the internet. all configuration done correctly step by step.

1. Configure the LDAP server (Bind type - Reguler)

2. Configure the single sign on (Enable polling)

3. Configure the IPv4 policy

 

but after these steps LAN users can't access the internet. 

Best answer by sw2090

To be correct:

 

It does block the complete internet if it has no valid license or cannot reach the Fortiguard Servers to check.

 

Maybe you could use flow debug to see what your packets are doing on your fgt.

 

  diag debug enable

  diag debug flow filter <filter|list|?> (a "?" will have it show available filters , "list" will list the current filters)

  diag debug flow show console enable (you want to see something on cli do you *g*)

  diag debug flow trace start <numberofpackets> (stop will stop it again)

 

Mostly this gives you a clue what goes wrong with your packets...

2 replies

FrancoisSogeclair
New Member
June 5, 2018

I'm not expert of Fortigate but i had same trouble because my licence was down.

 

YASH1994
YASH1994Author
New Member
June 5, 2018

In our side licence is ok. Thank you for the help.

andreotta
New Member
June 14, 2018

Hi,

Can FGT reach the Fortigaurdserver ? Can you try from FGT: #

exec ping service.fortiguard.net

 

Regards,

André Otta

McEathron
New Member
August 24, 2018

Hello YASH1984,

 

The Web Filter blocks websites based upon categories. It doesn't block the entire internet, just pages that Fortinet has determined fall into specific categories, that you have chosen to block.

 

For this reason, I would think that your Web Filter is not the issue here. The difficulty reaching the internet is more likely found in the setup of your LDAP, SSO, or IPv4 Policy.

 

Those are the area's that I would focus my troubleshooting on.

marco_d
New Member
August 24, 2018

I just updated our 240d cluster for 5.4.9 to 5.6.5 After the reboot the webfilter not worked more. There comes the message that no fortiguard server are avaible. I wait this night to see if there is some chage tomorrow. If not i will open a ticket. For the moment i disabled the webfilter what is not good but i not see any other option.

 

Regards

Marco

 

SecurityPlus
Explorer III
August 24, 2018

Do you have a green check by the Web Filter licenses on the Dashboard?

 

Can you: exec ping servicelfortiguard.net