FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
caunon
Staff
Staff
Article Id 359883
Description

This article describes how to avoid an issue where the gui-explicit-proxy setting via CLI command or Explicit Proxy via GUI of FortiGate has been disabled automatically after rebooting the FortiGate unit or upgrading the FortiGate firmware version.

Scope

FortiGate  v7.4.x.

Solution

 

  1. This issue may occur when setting gui-explicit-proxy to 'enable' via a CLI command or when enabling Explicit Proxy via the GUI of a FortiGate unit, as shown below. 

 

  1. CLI command:

 

 

config system settings

    set gui-proxy-inspection enable

    set gui-explicit-proxy enable

end

 

 

  1. In the GUI of FortiGate: Under FortiGate -> System -> Feature Visibility -> Security Features -> Explicit Proxy -> Tick to enable it -> Apply.

 

  

1.png

 

 

  1. When rebooting a FortiGate unit or upgrading a FortiGate firmware version, the 'gui-explicit-proxy' setting has been disabled automatically, or Explicit Proxy via the GUI of FortiGate has been disabled automatically.

 

To fix this:

 

 

  1. For a workaround for a temporary fix:

 

  1. Enable gui-explicit-proxy via a CLI command.

 

config system settings

    set gui-explicit-proxy enable

end

 

  1. Enable Explicit Proxy via the GUI under FortiGate -> System -> Feature Visibility -> Security Features -> Explicit Proxy -> Tick to enable it -> Apply.

 

  1. For a permanent fix, upgrade the FortiGate firmware version to be 7.4.5 and above.
Contributors