Description | This article describes that when Firewall policies are in a flow-based inspection, the FortiGuard block page does not display. |
Scope | FortiGate, FortiOS v7.0.x version. |
Solution |
The FortiGate devices running on FortiOS v7.0.x, are configured with Flow-Based Inspection mode firewall policies. In this case, while the device blocks websites according to the web filter profile, the expected FortiGuard block page is not displayed. Instead, users receive an error 'ERR_SSL_PROTOCOL_ERROR'.
When certificate inspection is enabled alongside a web filter profile on a firewall policy, the FortiGuard block page should normally appear for websites blocked by the web filter.
Or check the IPS Engine version by running the following command:
diagnose autoupdate versions | grep 'Attack Engine' -A
Once the IPS Engine is upgraded to version v7.0189, FortiGate will display the FortiGuard block replacement message as expected. |