Hey guys!
Problem: Users in the company receiving message "ERR_EMPTY_RESPONSE" when using Google Chrome to access WhatsappWeb, Instagram and Facebook. Chrome is the company's default browser. We did tests using Microsoft Edge and everything works normally, the problem is with Chrome. Clear browser caches, restore settings, reinstall Chrome, clear DNS cache, etc. Nothing our field service did worked, but it works with Edge.
I created a rule granting full access for one computer (without asking for authentication and without any filters), everything worked in Chrome. In other words, there is some combination of access rule + Chrome + websites (Whatsapp, Facebook and Instagram) that is blocking this access on Fortigate, but that does not harm the Edge browser. Has anyone here dealt with a similar problem?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @Nascimento,
Are you using webfilter and proxy based policy? Can you check Web Filter event logs? Do you see this error this error "unknown content-encoding detected and blocked"?
Regards,
Thanks for your response. I disabled Application Control and IPS in the Policy that allows access and so the access works. Either with IPS enabled or Application Control enabled, access stops working only for Chrome accessing Instagram, Facebook and WhatsAppWeb. So I still don't understand what is really happening.
Hi,
- Was this working fine before? Were there any changes in the Firewall configuration?
- What is the Chrome version you are using?
- In the Application Control are you blocking any application?
- Could you share the configuration of the Policy?
Regards,
Shiva
Yes it was working fine before. I upgraded the Fortigate to FortiOS v6.4.15 build2095 (GA). The Chrome is on version 122.0.6261.69 (Official Version) 64-bit. In Application Control I'm not blocking any application.
Same problem for me.
In proxy based policy, with IPS and App control I can't access FB and Instagram when I use Chrome.
It works when I use Firefox.
No problem in flow based policy
FGT-80F v7.4.3
Same problem for me.
However, if I disable Zstd encoding on Chrome, it works.
-> chrome://flags/#enable-zstd-content-encoding <-
Does Fortigate support this type of encoding in proxy based policy?
Thanks for your tip!
I have now switched off zstd via GPO.
Hi @GonA,
Zstd is not supported as of now. It is being worked on. You can disable zstd on Chrome or set "unknown-content-encoding" to "inspect".
# config firewall profile-protocol-options
# edit <>
# config http
# set unknown-content-encoding inspect
# end
For more information, please refer to https://community.fortinet.com/t5/FortiGate/Technical-Tip-usage-of-quot-unknown-content-encoding-quo...
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1634 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.