Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AHoffpauir
New Contributor II

Fortigate 30G can't add AntiVirus and Web Filter profiles to Firewall Policies

I am having an issue with AntiVirus and Web Filter. I have profiles created but I can't add them in the firewall policies. It has a field to add them but the drop down list doesn't show any of the created profiles.
FortiGate-30G
v7.2.8 build6390 (Mature)

Fortigate 30G Profile in Policies issue.JPG

1 Solution
mzainuddinahm
Staff & Editor
Staff & Editor

Currently, this is being investigated by the engineering team on Fortigate/FortiWiFi 30/31G running FortiOS 7.2.8GA.

 

Workaround:

Until this is fixed, the Webfilter & Antivirus profiles can be enabled using the CLI

 

config firewall policy
edit <policyid>

set utm-status enable

set av-profile <profile_name>

set webfilter-profile <profile_name>

end

MZA

View solution in original post

23 REPLIES 23
AHoffpauir
New Contributor II

I still haven't found a fix for this, any ideas?

sjoshi

can you let me know your exact FGT version? Is it in v7.4+ version

Also the model is 30G ryt?

If you have found a solution, please like and accept it to make it easily accessible to others.
Fortinet Certified Expert (FCX) | #NSE8-003459
Salon Raj Joshi
AHoffpauir
New Contributor II

FortiGate-30G
v7.2.8 build6390 (Mature)
I included this information in the original post

AHoffpauir
New Contributor II

v7.2.8 build6390 (Mature) seems to be the only version for the FortiGate-30G

sjoshi

from the snapshot the webfilter is on flow mode only. So regardless of proxy/flow mode on the firewall policy you should be able to select the profile. Now further have you tried it from the CLI to select the profile?

I verified in my lab in 7.2.8 and there is no issue and on top of that I'm getting the option of selecting the feature set also on the GUI/CLI.

Only from v7.4.4 for small end model the proxy feature has been disable

config firewall policy
edit <> >> policy ID
set webfilter-profile ? >> di a ? to see if the webfilter profile are coming

If you have found a solution, please like and accept it to make it easily accessible to others.
Fortinet Certified Expert (FCX) | #NSE8-003459
Salon Raj Joshi
AHoffpauir
New Contributor II

It is disconcerting that this firewall doesn't support URL or Virus protection on the firewall policies. I have been running without this protection since the firewall has been installed with no solution.

The only code available for the 30G seems to be v7.2.8 build6390 (Mature)

Am I the only one running the 30G? Is there any 30G that the support people can use to test with?

AHoffpauir
New Contributor II

I did as you asked and it still shows no AV or Webfilter on the policyFortigate 30G Profile in Policies issue 6.JPGFortigate 30G Profile in Policies issue 7.JPG

AHoffpauir

I was able to get the CLI to assign the AV and Web Filter profiles but they don't seem to be working. I blocked sites but users are not blocked. In fact, web sites are not showing up in the FortiView Web Sites tab at all.

pminarik

Your firewall policy screenshot shows "SSL Inspection: no-inspection".

You need at minimum "certificate-inspection" (For webfilter rating/blocking ONLY), or "deep-inspection" for inspection of the inner content (e.g. antivirus).

[ corrections always welcome ]
AHoffpauir
New Contributor II

I tried all combinations with the same results.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors