Users from a company network has Internet connection and doesn’t experience any problems with network.
But the FortiGate doesn’t block web pages by the Web Filter.
The debug output of the Web Filter shows the reason:msg="Policy allows URLs when a rating error occurs" user="N/A" src=10.188.3.239 sport=50465 dst=185.60.216.35 dport=80 service="http" hostname="facebook.com" status=passthrough error="all Fortiguard servers failed to respond" url="/"
msg="received a request /tmp/.ipsengine_213_0_0.url.socket, addr_len=37: d=facebook.com:443, id=9, cat=255, vfname='VDOM-A', vfid=2, profile='cust-vdom-A-webfilter-profile', type=1, client=10.188.3.239, url_source=3, url="/"
msg="Cache miss" user="N/A" src=10.188.3.239 sport=50466 dst=185.60.216.35 dport=443 service="https" hostname="facebook.com" url="/"
msg="received a request /tmp/.ipsengine_214_0_0.url.socket, addr_len=37: d=facebook.com:443, id=13, cat=255, vfname='VDOM-A', vfid=2, profile='cust-vdom-A-webfilter-profile', type=1, client=10.188.3.239, url_source=3, url="/"
msg="Cache miss" user="N/A" src=10.188.3.239 sport=50505 dst=185.60.216.35 dport=443 service="https" hostname="facebook.com" url="/"
action=10(ftgd-block) wf-act=3(BLOCK) user="N/A" src=10.188.3.239 sport=50505 dst=185.60.216.35 dport=443 service="https" cat=37 hostname="facebook.com" url="/"
Related Articles
Technical Note: Traffic Types and TCP/UDP Ports used by Fortinet Products