Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
pblazey
New Contributor

FC EMS blocking a URL that is not a valid FQDN

Hi,

Got a bit of a weird issue with our EMS.

 

Users are somehow generating a link that looks like data[:]application/9IZCADpxCi (random text follows) (without square brackets). I can see in our FortiAnalyzer there's a log for them looking up the "rating" of this URL, and it comes back as unrated (obviously, it's not a real, reachable or resolvable FQDN). I've tried exempting both data[:]application (without square brackets) and http://data/* from the web filter, which syncs from the FortiGate to EMS (as this is the URL that FC EMS actually logs as being blocked) but FC EMS is still blocking the URL locally on the user's device.

 

I'm no expert with this stuff, but this seems like a URL used to access a local server/filestore or something like that? I'm really not sure, it's obviously not resolvable over the internet, I've run Wireshark capture and can see that my network adapter doesn't send a DNS query when I enter this URL into my browser.

 

Any advice would be greatly appreciated

1 REPLY 1
ozkanaltas
Valued Contributor II

Hello @pblazey 

 

Can you try that "data:*" and "data[:]*"?

 

Also, you can allow unrated websites on FortiClient. 

 

image.png

 

 

 

 

 

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors