Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tgps26
New Contributor

No "https://www" returns web page blocked

Solved! :)

2 REPLIES 2
Dave_Hall
Honored Contributor

Perform an nslookup on both agitapp.com and www.agitapp.com and you will find they resolve differently. 

 

If you have security event logging enabled on the firewall policy covering web traffic, check the web logs for the "flagged" event to see why it is blocked.  But from the screenshot, the error message says "Newly Observed domain" which likely means the site has not been rated yet by the FortiGuard servce.  You can of course, add that site to a local ratings override.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
sw2090
SuperUser
SuperUser

Accoarding to your Screenshots the http Site is blocked by webfilter by FortiGuard(tm) Category .

You didn't write if that is wanted behaviour. If it is not check wether you have a rating override into an allowed cathegory for it or allow the cathegory. Also if you use webfilter check your rules. If it is allowed by url filter but thus blocked by webfilter set the accoarding url filter rule to exempt instead of allow to prevent this.

 

If wanted behaviour should be to block both http and https check if you have ssl inspection enabled on the corresponding policy and if in ssl inspection profile https is enabled and the cathegory is not in the trusted sites list.

 

hth

Sebastian

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors