Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
nawin
New Contributor

Perticular website not accessible through fortigate 600c FortiOS 5.0

Hello All,

 

I have been facing a issue from last few days, i am not able to access https://slack.com, "https://hubspot.com" both URLs.

Same URLs are working properly before. We are not using any Webfilter, Application Control, IPS or AV on our firewall.

 

I tried to upgrade the OS to 5.2 but still same the results.

 

There is no issue with internet service provide end.

 

I observed in log that, the connection is closing immediately. What causing this issue ? 

Here i am sharing log screen shot.

 

Kindly Help.

 

Thanks in advance.

 

Regards

Naveen.D

 

 

 

nawindara
nawindara
1 Solution
Dave_Hall
Honored Contributor

Have you tried other sites that use HTTPS?  Make sure the time/date/timezone are correct on both the fgt and your workstation.  Try sniffing the traffic from the CLI; something along the lines of...

diag debug reset
diag debug flow filter saddr <source IP address>
diag debug flow filter dport 443
diag debug flow show console enable
diag debug flow trace start 1000
diag debug en

or simpler...

diag debug reset
diag debug flow filter saddr <source IP address>
diag debug flow show console enable
diag debug flow trace start 1000
diag debug en

 

 

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

View solution in original post

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
1 REPLY 1
Dave_Hall
Honored Contributor

Have you tried other sites that use HTTPS?  Make sure the time/date/timezone are correct on both the fgt and your workstation.  Try sniffing the traffic from the CLI; something along the lines of...

diag debug reset
diag debug flow filter saddr <source IP address>
diag debug flow filter dport 443
diag debug flow show console enable
diag debug flow trace start 1000
diag debug en

or simpler...

diag debug reset
diag debug flow filter saddr <source IP address>
diag debug flow show console enable
diag debug flow trace start 1000
diag debug en

 

 

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Labels
Top Kudoed Authors