Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
suzuye
New Contributor II

About Fortigate WebFilter

WebFilter is blocking a lot of traffic to the following URL.

It looks like it's Microsoft traffic, but the category is (Uncategorized).

Is this a feature that FortiGate is designed to block?

 

http://48.210.69.87/filestreamingservice/files/xxxxxxxxxxxxxxxxxxx==&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com 

("xxxxxxxxxxxxxxxxxxx" is a random string)

 

FortiOS 7.0.15

1 Solution
suzuye
New Contributor II

Hi, dingjerry_FTNT

After monitoring the situation for a few days, it appears that some of the communications related to Microsoft are still being blocked. Since there are a large number of Microsoft-related addresses, it seems that the addresses that cannot be categorized in time are being blocked and displayed in the logs.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-allow-Windows-update-blocked-by-For...

 

There are no issues such as the inability to perform Windows Update, but the logs become difficult to read, so I added the settings mentioned in the above URL.


After applying the settings, the logs have become easier to read.

I think this could be a feature that can be turned ON/OFF by default in the OS.

View solution in original post

7 REPLIES 7
dingjerry_FTNT

Hi @suzuye ,

 

Please check what category the URL belongs to here:

 

https://www.fortiguard.com/webfilter

 

I can see that "48.210.69.87" belongs to "Not Rated" category (NOT Uncategorized)

 

You can submit a request to categorize this URL:

 

https://www.fortiguard.com/faq/wfratingsubmit?url=48.210.69.87

 

Meanwhile, you may check this KB article on how to override the web rating for the specific URL:

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-web-rating-override-for-s...

 

Regards,

Jerry
suzuye

Hi, dingjerry_FTNT

 

Thank you for the information.

I knew about the following request method.

https://www.fortiguard.com/faq/wfratingsubmit

 

I have made several requests using this method and been categorized, but the address part of "48.210.69.87" changes frequently.

At times, I have made requests 2-3 times in a week.

Is there no other way than to continue this process forever?

 

In addition, the address part changes frequently, and there seem to be various patterns for the "1D.tlu.dl.delivery.mp.microsoft.com" part, as shown below.

officecdn.microsoft.com
2.tlu.dl.delivery.mp.microsoft.com
tlu.dl.delivery.mp.microsoft.com



 

Thank you in advance.

dingjerry_FTNT

Hi @suzuye ,

 

My guess is that the IP 48.210.69.87 might belong to a shared server and not under your control.

 

If so, you may not request recategorizing it. You may consider using the custom category or the static URL Filter to exempt it:

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-a-static-URL-filter-feature-to-allow...

Regards,

Jerry
suzuye

Hi, dingjerry_FTNT

 

Thank you for the information.

As a test, I set "*.mp.microsoft.com" as an exclusion in the static URL filter.

 

It seems that it is no longer blocked, but the log shows a lot of "passthrough" and it is hard to read.

 

It seems that communications that were not blocked due to correct categorization are also shown in the log as excluded targets.

 

In the end, since the log was hard to read, I deleted the "*.mp.microsoft.com" exclusion.

 

Thank you in advance.

 

dingjerry_FTNT

Hi @suzuye ,

 

If you want to allow "*.mp.microsoft.com" via the URL Filter and skip the FortiGuard category checking, please set the action to Exempt in the URL Filter configuration.

Regards,

Jerry
suzuye

Hi, dingjerry_FTNT


Sorry, earlier we had set it to "Exempt," but a large number of "passthrough" occurrences were observed.

It seems that the translation was not done properly by Google.

"WebFilter" has been acting up since Saturday, so that may be the cause of the incorrect categorization.

I'll wait and see for a few days.


Regards,

suzuye
New Contributor II

Hi, dingjerry_FTNT

After monitoring the situation for a few days, it appears that some of the communications related to Microsoft are still being blocked. Since there are a large number of Microsoft-related addresses, it seems that the addresses that cannot be categorized in time are being blocked and displayed in the logs.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-allow-Windows-update-blocked-by-For...

 

There are no issues such as the inability to perform Windows Update, but the logs become difficult to read, so I added the settings mentioned in the above URL.


After applying the settings, the logs have become easier to read.

I think this could be a feature that can be turned ON/OFF by default in the OS.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors