Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Grumman
New Contributor III

Block HTTPS website on Google Chrome

Hello,

 

I have sucessfully managed to block http and https traffic on my Fortigate 100D but for some reason, if I open Google Chrome, all blocked HTTPS sites are accessible wile HTTP sites remain blocked !!!

 

I tried with Safari and Firefox and both HTTP & HTTPS sites are blocked...

 

Is there any reason why Chrome is bypassing the firewall settings?

 

The settings on the firewall are:

SSL/SSH Inspection ON, blocking HTTPS traffic

WebFilter ON, blocking all websites (* wildcard - deny) and allowing only 3 specific ones.

IPv4 Policy that incorporates the above rules.

1 Solution
emnoc
Esteemed Contributor III

The diag debug flow is your best friend, run the command and with a filter on chrome and non-chrome client ipv4:port . If I had to  guess, one of the following is taking place

 

[ul]
  • The fw-policy is not correct or being match for the traffic from  the client(s)
  • The chrome client is using some external HTTPS proxy that the firewall is not matching ( i.e x.x.x.x port 8888 or 8123 or etc....)[/ul]

     

     

    For example on running  diag debug flow, search here on this forum.

     

     

  • PCNSE 

    NSE 

    StrongSwan  

    View solution in original post

    PCNSE NSE StrongSwan
    3 REPLIES 3
    emnoc
    Esteemed Contributor III

    The diag debug flow is your best friend, run the command and with a filter on chrome and non-chrome client ipv4:port . If I had to  guess, one of the following is taking place

     

    [ul]
  • The fw-policy is not correct or being match for the traffic from  the client(s)
  • The chrome client is using some external HTTPS proxy that the firewall is not matching ( i.e x.x.x.x port 8888 or 8123 or etc....)[/ul]

     

     

    For example on running  diag debug flow, search here on this forum.

     

     

  • PCNSE 

    NSE 

    StrongSwan  

    PCNSE NSE StrongSwan
    Grumman
    New Contributor III

    Thank you for your swift reply and suggestions.

     

    I tried to replicate this on my machine and it does the same thing...

    Traffic from all browsers is blocked except from Chrome...

    I have no proxy setting on Chrome or any other browser...

    Is Chrome using some built in SSL/SSH proxy of some sort that fortigate can't catch?

    emnoc
    Esteemed Contributor III

    The diag debug flow is your best friend

     

    see the above & stop guessing

     

    PCNSE 

    NSE 

    StrongSwan  

    PCNSE NSE StrongSwan
    Announcements

    Select Forum Responses to become Knowledge Articles!

    Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

    Labels
    Top Kudoed Authors