Skip to main content
latyeo
New Member
July 8, 2020
Solved

Web rating error

  • July 8, 2020
  • 5 replies
  • 48532 views

Hi   We recently upgraded from 6.0.5 to 6.0.9 and then changed the Fortiguard protocol from UDP to HTTPS.  Since then we are occasionally getting block messages 'An error occurred while trying to rate the website using the webfiltering service.

 

I've looked at the kb article https://kb.fortinet.com/k....do?externalID=FD33528 but am slightly confused about the sentence "This will allow users to access the web sites when a rating error occurs, and will allow the FortiGate unit to use the FortiGuard Web Filtering database that it has stored on the unit to rate the web site."   Can I just confirm that it means when it can't reach fortiguard it will rate the website using the local db and will allow/block access accordingly.  Just looking at the option on the FG "Allow websites when a rating error occurs" suggests that it is going to allow it whatever the rating is.   Thanks for your time

Best answer by TecnetRuss

When "Allow websites when a rating error occurs" is enabled it means:

 

  • If the rating for the URL is in the cache, the FortiGate will apply the matching profile action for that cached rating, e.g. block, warn, monitor, allow, etc.
  • If the rating for the URL is not in the cache, the FortiGate will default to "allow" and allow the traffic through.

Keep in mind that the "local DB" cache is only a cache of the ratings for recently visited websites.  It is a very small list compared to the full FortiGuard database.  With this setting enabled there is a very good chance that traffic will get through to sites that would otherwise be blocked, so enable it at your own risk.

 

The reason that "a rating error occurs" happens more often with HTTPS vs. UDP is that Fortinet doesn't seem to have the same capacity to handle HTTPS web ratings lookups compared to UDP.  If you run "diag debug rating" when in UDP mode vs. HTTPS mode you'll see that there are far more servers available to respond to UDP ratings lookups vs. HTTPS.

 

Russ

NSE7

5 replies

TecnetRuss
Visitor III
July 8, 2020

When "Allow websites when a rating error occurs" is enabled it means:

 

  • If the rating for the URL is in the cache, the FortiGate will apply the matching profile action for that cached rating, e.g. block, warn, monitor, allow, etc.
  • If the rating for the URL is not in the cache, the FortiGate will default to "allow" and allow the traffic through.

Keep in mind that the "local DB" cache is only a cache of the ratings for recently visited websites.  It is a very small list compared to the full FortiGuard database.  With this setting enabled there is a very good chance that traffic will get through to sites that would otherwise be blocked, so enable it at your own risk.

 

The reason that "a rating error occurs" happens more often with HTTPS vs. UDP is that Fortinet doesn't seem to have the same capacity to handle HTTPS web ratings lookups compared to UDP.  If you run "diag debug rating" when in UDP mode vs. HTTPS mode you'll see that there are far more servers available to respond to UDP ratings lookups vs. HTTPS.

 

Russ

NSE7

latyeo
latyeoAuthor
New Member
July 9, 2020

Thanks Russ, that makes sense now.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!