Skip to main content
BMDIT
New Member
February 5, 2020
Question

www.msftconnecttest.com/redirect - Giving "Unknown" Error

  • February 5, 2020
  • 4 replies
  • 9387 views

Ladies and Gentlemen:

 

Got a problem that I suspect others have run into...

 

A user of mine keeps getting a "URL blocked by Forticlient" error when she tries to connect to the Internet at hotels or airport lounges.  The funny thing is, she's the only user getting that error.  I've got a couple of other users in the same circumstances that aren't getting it.

 

They're running FortiClient 6.0.8.  I found a thread (https://forum.fortinet.com/tm.aspx?m=165626) that talks about something similar, so I tried exporting the config, making the suggested change, and re-importing the config.  No change - it still doesn't work.

 

Any ideas?

 

Thanks!

 

Sean

    4 replies

    tanr
    New Member
    February 5, 2020

    I'm not too familiar with FortiClient OffNet handling, but just wanted to make sure her client is set up to allow "Unrated"?  In case this is not a FortiGuard connection issue.

     

    Is it possible her machine somehow got set to use a custom port for FortiGuard communication (other than UDP 8888)?  Or that she's got a local firewall that is blocking FortiGuard communications when off net?

    BMDIT
    BMDITAuthor
    New Member
    February 5, 2020

    tanr wrote:

    I'm not too familiar with FortiClient OffNet handling, but just wanted to make sure her client is set up to allow "Unrated"?  In case this is not a FortiGuard connection issue.

     

    Is it possible her machine somehow got set to use a custom port for FortiGuard communication (other than UDP 8888)?  Or that she's got a local firewall that is blocking FortiGuard communications when off net?

    It's not telling her "Unrated", though.  It's telling her "Unknown".  And I've got the URL (msftconnecttest.com) flagged as an allowed site on our FortiGate.  The entire error is as follows:

     

    "FortiClient has been configured to block unrated URLs.

    This URL was categorized as unrated because the FortiGuard URL rating service is inaccessible."

     

    I took a look at the FortiClient config and can't see where it says to allow unrated URLs.  Any pointers?  Or is this something that I need to configure on the FortiGate, have her make a successful connection, and then try it?

     

    Thanks!

    tanr
    New Member
    February 5, 2020

    Are you using EMS to manage the FortiClient endpoints, or just doing it from the FortiGate? 

     

    If you're just managing it from the FortiGate without EMS then I think you can look at the FortiClient Compliance Profile that's getting applied and see which web filter profile it's using.  Verify that the web filter profile has the Unrated category allowed and "Allow websites when a rating error occurs" checked.

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!