- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Fortigate 30G can't add AntiVirus and Web Filter profiles to Firewall Policies
I am having an issue with AntiVirus and Web Filter. I have profiles created but I can't add them in the firewall policies. It has a field to add them but the drop down list doesn't show any of the created profiles.
FortiGate-30G
v7.2.8 build6390 (Mature)
 
Solved! Go to Solution.
- Labels:
-
Firewall policy
-
FortiGate
-
Security profile
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Currently, this is being investigated by the engineering team on Fortigate/FortiWiFi 30/31G running FortiOS 7.2.8GA.
Workaround:
Until this is fixed, the Webfilter & Antivirus profiles can be enabled using the CLI
config firewall policy
edit <policyid>
set utm-status enable
set av-profile <profile_name>
set webfilter-profile <profile_name>
end
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you create a proxy or flow based profile?
Change the firewall rule from one mode to another and confirm if the profiles created shown up.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I don't see an option for proxy or flow. I am trying both the default profiles that came with the firewall as well as profiles I created.
 
 
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is what I am seeing when I try to apply a profile to a policy, the list is blank even though I have profiles, I even used the "create" button to make a new one and it doesn't show up once made.
 
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
in the Webfilter and Antivirus security profile you must change the >Feature set< to "Flow based". Then you can see and select the profiles in the firewall-policy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There doesn't seem to be a ">Feature set<" option in the profiles, see above screen shot
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Fortinet has removed the proxy mode function from all Fortigate models with 2 GB RAM from firmware 7.4.4.
The Fortigate 50G only has 2 GB RAM and has only recently become available.
Fortinet may have removed the feature quickly and not properly from the firewall model firmware.
It can therefore not be ruled out that the first firmware still has a bug and that this will only be fixed in the next release.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Removing Antivirus and Web Filters from firewall policies seems like a pretty big Opsie for a NGFW
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
please check from the CLI and make sure if the firewall policy is in flow mode then the AV and webfilter should also be in flow mode.
config webfilter profile
edit "new-wf-profile"
set feature-set {flow | proxy}
end
Salon Raj Joshi
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There is no "feature-set" set command (see attached screenshot)
 
