Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
TrevorCampbell
New Contributor

403 Forbidden: incorrect proxy service was requested

Hi I hope this is in the right forum... I have an issue with a site trying to open PDF' s from some websites (not all). Windows 2003 running Citrix Presentation server IE 8 Adobe Reader 8 FortiWiFi 60C, Firmware 4.0 MR2 Patch 7. Explicit proxy on FortiWiFi enabled. NTLM Authentication with AD Groups using FSSO Users are trying to open a PDF document using a URL straight to the PDF that was e-mailed to them (ie: not a link on the website). The site is classified as a " Job Search" site however this is not blocked for all staff. The staff that have access to this site are able to view the site homepage etc. When they try to open the PDF they get a " 403 Forbidden: incorrect proxy service was requested" returned by the FortiWiFi. If I use a htm file with a href link and then right click this -> " Save target as" they get the error: " IE was not able to open this internet site. The requested site is either unavailable or cannot be found" The WebFilter logs show it is hitting the correct rule and profile and no error as far as I can tell. I' ve also tried the following: 1. PDF' s from other sites and they work correctly. 2. A local .htm file with a href to the PDF, rather than click on the URL in the e-mail or copy / paste the URL into IE - still get the 403 error. 3. A .htm file on an (external) web server (to ensure IE is authenticated to the proxy first) - still get the 403 error. 4. Bypassing the proxy for the website (either as an exclude or turning off proxy) - works but there is no identity based policies applied so no NTLM. I' m not able to replicate this on our test servers but they' re running Win 2008 / Adobe Reader 9. A google search turns up a few references to Adobe Reader and NTLM authentication not working well but was hoping to confirm that in some way, especially since it works for some PDF' s but not others ? Is there any diagnose commands that the output of would be helpful ? Thanks in advance Trevor.
Trevor
Trevor
3 REPLIES 3
ede_pfau
SuperUser
SuperUser

Hi, it might be that there is some content embedded in the PDF that requires external sites, e.g. Flash. I think there were other posts about Adobe servers that had to be accessible for some PDFs. Test: allow ALL services from LAN to WAN and try to open the PDF.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
TrevorCampbell
New Contributor

Hi Everyone I' ve done some more testing and found that the larger the PDF the more likely it will fail. I' m thinking I might need to raise a support case with Fortinet. I' ve grabbed a number of the Fortinet manuals of various sizes and dropped them on one of our external web servers. I can replicated the issue using a FortiWiFi 60C and a domain joined XP machine. I have deliberately NOT installed Adobe reader for testing. If I use the proxy server I have found: I can download and save PDF' s up to around 350KB without issue every time. I try to download a PDF of around 600KB or larger it pretty much fails all the time. The one test PDF I have between these sizes (450KB) works sometimes but fails other times. I' ve cleared the IE cache between each test to rule out IE getting the file from Cache. If I configure the XP machine to not use a proxy but with the FortiGate as its gateway and with a firewall policy setup as follows I can download PDF' s of at least 3.3MB. (I' ve not tried larger at this stage). Source Address = Test machine IP Destination = WAN1 NAT Enabled Identity based policy - identical to the Web proxy Identity based policy All that I have enabled is: UTM: 1. Protocol options 2. Enable Anti-Virus 3. Enable Web Filter all set the same in my web proxy identity based policy. This essentially matches the Web Proxy policy - the only difference being that Source interface / Zone and for the web proxy I have left source address at " all" . I need to work out the issue with the explicit proxy because I need this to work for Terminal servers so can' t I can' t do this based on IP address. Thanks in advance Trevor
Trevor
Trevor
TrevorCampbell
New Contributor

I' ve got an update on this issue (finally) after talking with FortiNet support. It seems there is a performance issue with version 4.254 of the AV Engine. I was given a link to version 4.257 and the issue appears to have been resolved (at least my preliminary testing so far shows this - fingers crossed). Now my only question is how do we know when there has been an update to the AV Engine and where do we get it from when we do find out ? Trevor.
Trevor
Trevor
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors