Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Damir
New Contributor

FortiGate Blocking Access to Gmail Intrusion Prevention Triggered

Hello Fortinet Community,

I am experiencing an issue where our FortiGate device is blocking access to Gmail.
When users try to access Gmail, they receive a message stating Intrusion Prevention Triggered and their attempt is blocked.
Here is the relevant message displayed:

Your attempt to access the Internet resource is blocked by Intrusion Prevention.

I have attached a screenshot for reference.
Has anyone else experienced a similar problem with FortiGate blocking access to Gmail or other Google services?
Any advice or guidance on how to troubleshoot or configure exceptions for this would be appreciated.
Thank you!

Edit: I have added 2 new screenshots with more details.

 

 

Screenshot 2025-08-04 120323.png

Screenshot 2025-08-05 103724.pngScreenshot 2025-08-05 103747.png

 

 

6 REPLIES 6
jacob351
New Contributor

If there is not VPN, there has to be a Fortinet firewall on your network or upstream blocking your connections or trying to do deep ssl inspection on your traffic.

10.0.0.0.1 192.168.1.254
Damir
New Contributor

Thank you for your response.
That's right, I set up a Fortigate firewall on the network, and everything was working fine - Gmail was loading as it should.
Since the weekend, an issue started happening: when trying to load the Gmail app, it begins to load but then stops and shows the error "Numerical error 4."
When I open the developer console, there are errors, and the image shows one of them.

filiaks1

So use the HAR file to check the url of the image being blocked. Maybe check the logs why the image url was blocked. 

 

Also check the cache and optimization if they are intefiring with the IPS.

 

Cache service and video caching | FortiGate / FortiOS 7.6.3 | Fortinet Document Library

 

Protocol optimization | FortiGate / FortiOS 7.6.3 | Fortinet Document Library

Damir
New Contributor

I have added 2 new screenshots with more details.

funkylicious

it appears that this IPS signature got triggered/observed on multiple devices in the last couple of days.

https://www.fortiguard.com/encyclopedia/ips/11393 

the default action is pass, by i pressume that you created a custom IPS profile where it get's overwritten with block, so if the error doesnt really present a security risk i would suggest putting it in pass, this signature only.

"jack of all trades, master of none"
"jack of all trades, master of none"
Damir

We have a custom IPS profile where the action for this specific signature was set to "block." Currently, I have added an exception for "mail.google.com" in the deep inspection profile.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors