Created on
10-29-2025
03:57 AM
Edited on
11-23-2025
10:41 PM
By
Jean-Philippe_P
| Description | This article describes how to troubleshoot and resolve issues where FortiGate fails to block adult or restricted HTTPS websites due to encrypted traffic (HTTPS / TLS 1.3 ECH). |
| Scope | FortiGate. |
| Solution |
Administrators may observe that FortiGate fails to block adult or restricted websites even when Web Filter and URL Filter profiles are properly configured. Symptoms:
Root Cause: Most adult sites and large CDN-hosted domains (e.g., Cloudflare, Akamai) use HTTPS with Encrypted Client Hello (ECH). Without Deep SSL Inspection, FortiGate cannot decrypt and read the true URL or hostname inside the TLS 1.3 session, resulting in failed filtering.
Note: SNI may still appear in the Encrypted Client Hello, but this is the outer SNI, which is sent in clear text. Refer to this article for more info: Technical Tip: How to block TLS 1.3 Encrypted Client Hello (ECH) in FortiGate firewalls.
*cloudflare-ech* *whos.amung*
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.