- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FortiGate WebFilter Issue
Hi guys,
We would like to seek similar encountered issue and how did you guys resolve this. We're currently encountering an issue regarding our Web Filter as wherein all access going through internet policies with Web Filter encountered web rating error occured. Had to create a temporary policy without added WebFilter Profile however this impose risks.
What should be the workaround for this one for it to work properly again? Suggestions are highly appreciated. Thank you in advance.
- Labels:
-
FortiGate
-
Web profile
-
Web rating
- « Previous
-
- 1
- 2
- Next »
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There are users working, so I’ll try late at night. In any case, support needs to look into the issue because I see that many devices are having problems.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Let us know if it worked already on your end later tonight, so we can try to enable it again tomorrow.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Sir,
Can you please try to disable Fortiguard unicast and used protocol udp with port 53.
the Anycast method to address the Fortiguard servers. Relying on Fortinet DNS servers, the FortiGate will get a single IP address for the domain name of each FortiGuard service. If you disable anycast you will get few more Fortiguard server ip address for connection.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGuard-is-not-reachable-via-Anycast-de...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi, the same problem in Poland. I have to disable web filtering on firewall policys.
Do you know when this will be fixed?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I haven’t tried it yet, but I think it’s been fixed. If you’re still experiencing issues, go to Policy & Objects --> Firewall Policy --> edit your outgoing policy and disable Web Filter.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@connectbv do you have fortiguard-anycast disable or enabled in your config ?
You can check it through following:
#config system fortiguard
#show full | grep anycast
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Now I looked immediately and got this result. But I noticed that the FortiGuard service is currently UP.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please try to change the fortiguard settings to these:
config system fortiguard
set fortiguard-anycast disable
set protocol udp
set port 53
set sdns-server-ip 208.91.112.220
set source-ip <WAN IP>
end
If you are using SD WAN then make sure this setting is configured:
config system fortiguard
set interface-select-method sdwan
end
After that check the fortiguard connectivity using this command:
di deb rating
If you are still having issue you can configure the webfilter to allow traffic when rating error occurs until the issue is resolved:
Regards,
Varun

- « Previous
-
- 1
- 2
- Next »