Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ashok_kumar
New Contributor

Can' t block Twitter,Flicker and apple.com

Dear Friends, We are using Fortigate 200 Din our office . Almost unwanted sites are blocked via this fortigate,but unfortunately we cant block these three websites.Can any one help me on this issue. Thanks..

ashok kumar

Network Engineer

CCNP/MCSA

 

ashok kumar Network Engineer CCNP/MCSA
45 REPLIES 45
ashok_kumar
New Contributor

Yes did but still its working

ashok kumar

Network Engineer

CCNP/MCSA

 

ashok kumar Network Engineer CCNP/MCSA
hklb
Contributor II

Sorry, I updated my last post. You need to create wildcard with *twitter.* . apple : wildcard *.apple.* flickr : wildcard *.flickr.* At home it works with this config.
ashok_kumar
New Contributor

www.apple.com is blocked,but https://www.apple.com is working.twitter and flickr still working

ashok kumar

Network Engineer

CCNP/MCSA

 

ashok kumar Network Engineer CCNP/MCSA
hklb
Contributor II

Could you please take a print screen of the certificate of https://www.apple.com ?
ashok_kumar
New Contributor

Yes done

ashok kumar

Network Engineer

CCNP/MCSA

 

ashok kumar Network Engineer CCNP/MCSA
ashok_kumar
New Contributor

DNS resolves ' www.apple.com' to 23.211.11.213 HTTP Server Header: Apache SSL certificate Common Name = www.apple.com Subject Alternative Names = www.apple.com Issuer = Symantec Class 3 EV SSL CA - G3 Serial Number = 52C3FD89F2C5378450FE53AC1A747974 SHA1 Thumbprint = 2191CB76D235BC638904F43B0E70B913A43924C6 Key Length = 2048 bit Signature algorithm = SHA256 + RSA (excellent) Secure Renegotiation: Supported This certificate does not use a vulnerable Debian key (this is good) SSL Certificate has not been revoked OCSP Staple: Not Enabled OCSP Origin: Good CRL Status: Good SSL Certificate expiration The certificate expires April 16, 2016 (597 days from today) Certificate Name matches www.apple.com Subject www.apple.com Valid from 16/Apr/2014 to 16/Apr/2016 Issuer Symantec Class 3 EV SSL CA - G3 Subject Symantec Class 3 EV SSL CA - G3 Valid from 31/Oct/2013 to 30/Oct/2023 Issuer VeriSign Class 3 Public Primary Certification Authority - G5 Subject VeriSign Class 3 Public Primary Certification Authority - G5 Valid from 08/Nov/2006 to 07/Nov/2021 Issuer VeriSign, Inc. SSL Certificate is correctly installed Congratulations! This certificate is correctly installed.

ashok kumar

Network Engineer

CCNP/MCSA

 

ashok kumar Network Engineer CCNP/MCSA
Bromont_FTNT
Staff
Staff

Show us a screenshot of your firewall policy... Make sure SSL/SSH inspection is ON
ashok_kumar
New Contributor

Please find the attachmnet

ashok kumar

Network Engineer

CCNP/MCSA

 

ashok kumar Network Engineer CCNP/MCSA
ashok_kumar
New Contributor

fyi

ashok kumar

Network Engineer

CCNP/MCSA

 

ashok kumar Network Engineer CCNP/MCSA
Bromont_FTNT
Staff
Staff

I can' t see if SSL/SSH inspection is turned " on" on the specific firewall policy allowing traffic out to the internet. Can you show that screenshot?
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors