Hello,
I have two FG 500E in HA configuration.
I just did a sw upgrade on them which seems to have been completed successfully.
The previus version was 7.4.2 and the current is 7.4.5 build 2702.
Now I cannot access most of websites because I get the error: PR_CONNECT_RESET_ERROR.
The network is working and by excluding the fortigate from the path I can regain the access to the websites.
Many thanks for any help.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
Thank you for the details provided. The error PR_CONNECT_RESET_ERROR typically indicates that connections are being reset, which can happen if SSL inspection or certificate handling has changed after the upgrade.
Here are a few steps to troubleshoot:
If the problem persists, please can call us at the support line and create a ticket, "http://www.fortinet.com/support/contact_support.html"(Select your country from the link to see the regional support number), if you require immediate assistance and quote this ticket number or update this ticket.
Thanks,
Thank you Raghuram for your quick asnwer,
about SSL/Deep Packet Inspection:
I switched to simple certificate inspection, but nothing changes;
about certificates:
I'm not sure, my fortigates hold a long list of valid certificates. Strangely, the web interface seems to use a self-signed certificate. However, we cannot install a certificate in each client browser because we have too many users and browsers.
Before the update, the above described problem did not exist.
about review logs:
In the Traffic domain, Log & Report, Security Events, SSL, there are a lot of entries of with action "blocked". No log entries regarding antivirus or intrusion prevention.
These FG500E make a virtual wire pair, so I can easily exclude them from the network path, but each test requires two network outages with no web browsing in between until a solution is found.
Can you suggest something else to try?
For anyone who might find this result useful: After a few days of working to fix the problem, we found that in the security profiles, ssl/ssh inspection, our-profile by disabling the SNI server certificate, web browsing became normal.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.