Skip to main content
Ouams_90
Explorer
February 12, 2025
Question

WEBFILTER NOT WORKING

  • February 12, 2025
  • 15 replies
  • 3833 views

hello , here jai two wan the first is set up for ipsec the second is to go to internet I have a problem with the webfilter when I put a web filter in a policy via wan 1 PPPOE the webfilter its work but when I put it on the wan 2 ip manual the webfilter blocks everything

15 replies

Dhruvin_patel
Staff
Staff
February 12, 2025

Greetings!

 

Are you using the same web filter profile that one is being used with a policy that has an outgoing interface as a pppoe link in a policy where the outgoing interface is wan1?

 

Regards!

Ouams_90
Ouams_90Author
Explorer
February 12, 2025

thank you for your answer

yes, it's the same profl

please note that :

route static wan 1 manual
route static wan 2 pppoe dynamique

distance adminitrative wan 1 et 2 = 1

wan 1 priority =1
wan 2 priority = 2

AEK
SuperUser
SuperUser
February 12, 2025

It I understand well your case, it seems the reason is that your clients are reaching Internet through WAN1, not through WAN2, due to your current default route configuration, because PPPoE has by default the priority as default route.

Bear in mind the best way to manage multiple interfaces is SD-WAN.

You can start here:

https://docs.fortinet.com/document/fortigate/7.2.10/administration-guide/889544/sd-wan-quick-start

In case you don't want to use SD-WAN then you just need to configure your static default route (through WAN2) with a distance = 4 or less.

AEK
Ouams_90
Ouams_90Author
Explorer
February 12, 2025

thank you for your reply

currently
the traffic is just based on wan 1 since it is configured in ippool

wan 2 is configured for RDP port forwarding

 

 

dingjerry_FTNT
Staff
Staff
February 12, 2025

Hi @Ouams_90 ,

 

1) If the same web filtering profile is working at least with one firewall policy, there should be no configuration issue with the profile;

 

2) Even if your WAN2 interface has no Internet access, it doesn't matter.  The web filtering rating is sent by FGT itself to the FortiGuard servers based on the routing table.

 

So you may provide the screenshot of the block message for the users got with the traffic via the WAN2 interface.

 

If you have some web filter raw logs for this issue, that would be much better. 

Ouams_90
Ouams_90Author
Explorer
February 13, 2025

Hi @dingjerry_FTNT 

thank you for your reply
here are some screen captures no access to internet site no securiser et capture log web filter et ssl inspection.

Capture d'écran 2025-02-13 082548.pngCapture d'écran 2025-02-13 083211.pngCapture d'écran 2025-02-13 083825.png

dingjerry_FTNT
Staff
Staff
February 13, 2025

Hi @Ouams_90 ,

 

Can you double click on one block log message to check the details?  Or if you can save it and provide one RAW log message, that would be great.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!