FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
dbabic
Staff
Staff
Article Id 196276

Description

 

This article describes how to allow users to access the internet when a rating error occurs.

Indeed, an error may occur whilst trying to rate a particular webfiltering service which results in the user seeing a 'Web Page Blocked' message when accessing the internet.


This may be caused by:

  • An issue about the rating of the FortiGuard Web Filtering feature.
  • The expiration of the Web Filtering license.

 


Scope

 

Web Filtering.


Solution

 

To allow users to access the internet is presented here for FortiOS v5.2 and v5.4.

This will allow users to access the websites when a rating error occurs and will allow the FortiGate unit to use the FortiGuard Web Filtering database that it has stored on the unit to rate the website.

This is applicable even if the FortiGuard Web Filtering license has expired but it will not allow access to the latest update from the FortiGuard service.

 

FortiOS.

Go to Security Profiles -> Web Filter.
Choose the Profile to use.
Go to Rating Options.
Enable 'Allow Websites When a Rating Error Occurs'.

 


On FortiOS 6.4 and later, 'Fortiguard-anycast' can be disabled, and set the protocol and port to UDP and port 8888.

Change the FortiGuard settings as below when a rating error occurs:

 

config system fortiguard

    set fortiguard-anycast disable

    set protocol udp

    set port 8888

end