Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Kubajs
New Contributor III

Policy based - URL categories does't work

Hello,
I'm using policy-based mode on FortiGate and I have a problem with URL filtering. I have set up the rules as described here https://docs.fortinet.com/document/fortigate/7.2.0/new-features/472314/allow-web-filter-category-gro... and I have the rule targeting a user group. In the log, I see a deny rule that says the page is Unrated, but on the https://www.fortiguard.com/webfilter site, I can see that the page has a category.

I am sending log:

date=2023-12-16 time=16:33:02 eventtime=1702740782183012282 tz="+0100" logid="0316013056" type="utm" subtype="webfilter" eventtype="ftgd_blk" level="warning" vd="root" policyid=74 poluuid="7b975724-9285-51ee-f073-60f6db8bd24e" policytype="security-policy" sessionid=180151 user="Domain_user" authserver="FSSO_server" srcip=10.1.1.1 srcport=50104 srccountry="Reserved" srcintf="VLAN" srcintfrole="lan" srcuuid="efa45e5a-56d5-51ee-ff05-d73441199146" dstip=85.207.58.49 dstport=443 dstcountry="Czech Republic" dstintf="wan1" dstintfrole="wan" dstuuid="efa45e5a-56d5-51ee-ff05-d73441199146" proto=6 service="HTTPS" hostname="<website URL>" action="blocked" reqtype="direct" url="<website URL>" sentbyte=563 rcvdbyte=1460 direction="outgoing" msg="URL belongs to a denied category in policy" ratemethod="domain" cat=0 catdesc="Unrated"

 

I am completely lost :(

Can someone help me please?

Thanks

1 Solution
mle2802

Hi @Kubajs,
Can you tried this command

config system fortiguard
set webfilter-force-off disable
end

Then close browser and try to browse again to see if the website still being blocked. Also after making the change, use "diag debug rating" to confirm if web filter is enabled.

View solution in original post

15 REPLIES 15
mle2802

Hi @Kubajs.

Can you please try to ping update.fortiguard.net and service.fortiguard.net to see if they are resolvable?

Kubajs
New Contributor III

With no problem.FortiGuard2.jpg

mle2802

Hi @Kubajs,

Can you try to find this option

config system fortiguard
show full | grep webfilter-force-off

Kubajs
New Contributor III

Hello @mle2802 

Okay, I tried it:

FortiGuard4.jpg

mle2802

Hi @Kubajs,
Can you tried this command

config system fortiguard
set webfilter-force-off disable
end

Then close browser and try to browse again to see if the website still being blocked. Also after making the change, use "diag debug rating" to confirm if web filter is enabled.

Kubajs
New Contributor III

Hello @mle2802,

It is working :) thank you very much :)

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors