FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
abalachandran
Article Id 353066
Description This article describes the configuration requirements to when having FortiGuard webfilter categories set to ‘Warning’ in WCCP setup between FortiGate and FortiProxy.
Scope FortiGate, FortiProxy.
Solution

This article assumes there is already an existing setup working WCCP setup using FortiGate and FortiProxy. Refer to this article for further reference: Technical Tip: WCCP between FortiGate and FortiProxy

 

Whenever there are FortiGuard categories set to warning in the webfilter profile used in the FortiProxy for WCCP, it is required to ensure that the client device traffic to port 8010 is forwarded to the FortiProxy by the FortiGate for FortiGuard block and override pages to work.

 

Required configuration.

 

On FortiGate:

  1. On the firewall policy with WCCP enabled, ensure to allow port 8010.

 

From GUI:

 

image.png

 

From CLI:

 

image.png

 

  1. Create a custom entry to allow custom ports to be forwarded:

 

image.png

 

On FortiProxy:

  1. Add port 8010 under wccp settings:

 

image.png

 

The Issue observed before making the changes above:

 

image.png

 

image.png

 

 

The user device will run into an error upon selecting proceed on the FortiGuard warning page.

 

Post making the changes:

 

image.png

 

The site is reachable after selecting ‘Proceed’.