FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
nradia_FTNT
Staff
Staff
Article Id 336543
Description This article describes why there is the error ERR_CONNECTION_CLOSED when accessing a website even though the website category is allowed.
Scope

FortiGate  7.X.

Solution

Issue: ERR_CONNECTION_CLOSED Error When Accessing a website.

When attempting to access a website, an ERR_CONNECTION_CLOSED error is encountered despite the following configurations:

  • The website category is allowed in FortiGuard and is added to the URL filter as an exempt site.
  • Web Filter Category Override is enabled.
  • Logs display both allow and deny messages intermittently.
  • Debugging shows normal operations.
  • Geographic Country Block is not enabled, and the country is allowed.

 

However, the website still fails to open with the ERR_CONNECTION_CLOSED error when accessed via a browser.

 

Resolution.

To resolve this issue, add the website to the SSL inspection bypass or exemption list. This action should allow the website to open normally.

 

Procedure: Adding an FQDN to the SSL Inspection Bypass or Exemption List.

  1. Navigate to the SSL inspection settings in the Fortinet device.
  2. Locate the section for SSL inspection bypass or exemptions.
  3. Add the Fully Qualified Domain Name (FQDN) of the website that is experiencing the ERR_CONNECTION_CLOSED error.
  4. Save the configuration and apply the changes.

 

The website should now open without encountering the ERR_CONNECTION_CLOSED error.

 

Screenshots as below:

 ERR_CONNECTION_CLOSED.png

 

How to add FQDN in SSL inspection bypass or Exemption list:

 SSL EXEMPTION.png

 

Related article:

Technical Tip: Exempting applications from SSL Inspection