Description | This article describes how to troubleshoot content filtering problems. |
Scope | FortiGate version 7.2.8. |
Solution |
If content filtering is not working as expected for the configured web profiles, follow the troubleshooting steps below to identify the problem. This article focuses on possible problems that can occur when using content filtering as shown below:
Requested Page is not loading. (no error message shown, blank page) Requested Page is loading with blocked page replacement message from Fortigate after 2-3 minutes. Requested Page is loading after 2-3 minutes.
Example configuration for the matching policy :
edit 1 set inspection-mode proxy
Example configuration for the content filtering is shown below :
Fortigate# config webfilter content config webfilter content
Example SSL Inspection Profile Selected on the matching Policy : Fortigate# config firewall ssl-ssh-profile Fortigate# edit "custom-deep-inspection" <--- Default profile in FortiGate, select the custom profile if it exists. Fortigate# get (output is truncated) server-cert-mode : re-sign
Firewall policy mode Proxy and SSL Deep Inspection must be enabled on the corresponding policy for content filtering.
In this scenario, the user should receive a blocked replacement page from FortiGate :
Example below:
If the user is searching for a word, not in the block list, the page should load on the user screen without any problem.
If the user is experiencing problems (page not loading, it takes too much time to load) when searching listed or nonlisted words, change the setting under SSL Inspection Profile as below.
Fortigate# config firewall ssl-ssh-profile Fortigate# edit "custom-deep-inspection" <--- Select the profile enabled on the policy. Fortigate (custom-deep-insp~ion)# set supported-alpn http1-1 Fortigate (custom-deep-insp~ion)# end
The problem will be fixed and the page will opened or blocked depending on the configuration under the content filtering profile. This is a known issue and it is fixed in version 7.4 and version 7.2.11. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.