Hello,
I am performing an EICAR test on a FortiGate 60F running v7.4.6 with only the Antivirus feature enabled under Security Profiles in the policy.
While accessing the EICAR test files from Chrome, I noticed that sometimes the FortiGate displays the replacement block page, but other times it does not.
Do you know why the block page is not displayed in certain cases?
Here is what I observed:
・Block page does not appear
After clicking the download button, the FortiGate log shows that the file is blocked by Antivirus, but the browser displays “This site can't be reached” instead of the replacement block page.
Even on subsequent attempts, the block page does not appear.
- eicar.com
- eicar.com.txt
・Block page appears normally
After clicking the download button, the file is blocked by Antivirus and the browser correctly shows the replacement block page.
- eicar.com.zip
- eicar.com-2.zip
If anyone knows the reason for this difference in behavior, I would appreciate your insights.
Thank you.
The “replacement block page” is only shown when FortiGate can actually inject its own HTML page into the HTTP response stream.
In practice that happens for attachment‑type downloads (e.g., ZIP files) but not for content that the browser is expected to display inline (plain text, HTML, etc.).
When the EICAR file is served as a plain‑text or HTML document, the browser tries to render it directly.
FortiGate’s AV engine blocks the file, closes the connection, and the browser simply reports “This site can’t be reached.” Because the connection is terminated before any HTML can be sent, the replacement block page can’t be displayed.
For ZIP files the browser treats the response as an attachment, so FortiGate can replace the payload with its block‑page HTML and the user sees the expected page.
In short:
File type Browser behavior FortiGate action Result
.zip, .tar, etc. Attachment Replace payload with block page Block page shown
.txt, .html, .com Inline Close connection “This site can’t be reached”
If you want the block page for all blocked files, you need to enable the “Show block page” option in the policy (or use a Web Filter policy that forces a block page for all blocked content).
@Daniel__ mentioned a lot of things, I will only add check that you decrypt the traffic as well as eicar test site has http and https options.
| User | Count |
|---|---|
| 2910 | |
| 1450 | |
| 850 | |
| 825 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.