Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
bgoodwin
New Contributor

FortiGuard update causing major issues

I'm new here, so I hope this is the appropriate place for this post. I wanted to share an issue we experienced this week that may help others using FortiGate firewalls.

On Wednesday morning, we discovered that our classroom monitoring software—which allows teachers to view student Chromebook screens—had stopped functioning. I reported the issue to the vendor, and after some investigation, we found a pattern: all affected schools were FortiGate users.

Upon reviewing our FortiGate security logs, we identified that the vendor's domain had been flagged as a proxy, and FortiGuard was blocking its SSL certificate. Interestingly, we also noticed that several Apple domains were being flagged as proxies as well, which may explain why our Apple devices have been stalling or having trouble connecting to the internet.

After we added exceptions for the monitoring software domain in both the Web Filter and DNS Filter, everything began working properly again.

While I’m not sure how or why FortiGuard updates these proxy flags, these recent changes have consumed quite a bit of troubleshooting time. I wanted to post this in case others are experiencing similar issues—hopefully it can save you the same headache.

Billy Goodwin
Director of Technology
Billy GoodwinDirector of Technology
1 REPLY 1
MassimoCapra
New Contributor

Hello,
can you check whether your problem falls under this KB?

How to fix 'SSL connection is blocked... - Fortinet Community

In particular:

This behavior change is due to a change included in FortiOS v7.2.11 and v7.4.5. Engineering ID: 1004258.

See the FortiOS v7.4.5 release notes for more information.
(See ID 1004258 in "Changes in default behavior")

 

Best Regards

Massimo
Massimo
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors