Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
m_raza
New Contributor

FortiOS 5.2.2 issues

We have recently upgrade the FortiOS from 5.2.1 to 5.2.2 in our infrastructure 

Right now, we are facing issues with Web Filter Engine and SSL inspection, both of them are heavily malfunctioning and drop our legitimate traffic. Even web filtering is not filtering any web site which is extremely prohibited in our organization. 

We created some ipv4 policies where we apply web filtering to block all social sites category with out applying any application filtering because we can't due to some reasons and we created three explicit proxy policies where we applied multiple level of web filtering restriction. The failure we are facing is that in ipv4 policies web filtering is not working at all and in explicit proxy policies web filtering sometime works and some time don't. 

 

Its all happen after upgrading the OS from 5.2.1 to 5.2.2. We are using FortiGate 200D

 

If any one could help me regarding this issue

 

Thanks.

2 REPLIES 2
kernelkraut
New Contributor

I have exactly the same issue:

 

Upgraded a cluster of 200B's from 5.0.9 > 5.2.2 and noticed that my CPU usage went to 100%. I also noticed that most of my users could no longer browse the internet (web filter policies were not working). When I remove the FSSO groups from the web filtered policies then they work again and my CPU drops back down to a reasonable percentage. So I tested with a non-domain device which should get a prompt for NTLM credentials. Even though the policies all have NTLM enabled, I never get a prompt to authenticate. The browser is redirected to the https://firewall_ip/fgtauth? page but it just never prompts for credentials. I think thats what causing the 100% cpu usage as all my users connect...

 

I have tried recreating all the policies and all the LDAP and FSSO configs - None of which has solved the issue. 

 

I have logged the issue with support...

mac
New Contributor

Hi Raza,

Please disable SSL inspection & check webfilter LICENSE Has expired.

 

Hi kernelkraut,

Check whether the firmware upgrade format,

And Please move to the first POLICY.

 

Labels
Top Kudoed Authors