Hi folks,
this is no criticism to Fortinetsupport, but I am very interested whether you guys @the forum are having the same issues with Forticlient EMS and the webfilter.
I have a open ticket running since June 2022 and did numerous tests, debuglogs, new installs, adapt the installation etc.
Situation:
So you absolutly cannot rely on this part of Forticlient, which makes it some kind of insecure!
Does no one of you have this troubles? I cannot believe that I am the only one with this situation. Does you Forticlient-Webfilter work (does it block sites when going from on- to off-fabric?)
Some feedback woud be great!
Thanks a lot!
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello menatwork,
Thank you for using the Community Forum.
I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Regards,
Hi,
as no one replied it seems like no one have got this issues, or cannot replicate it? Really interesting....
Hello,
I will try to find a FortiClient expert for you, like the other post.
Regards,
Hi menatwork,
In my personal experience, web filter works reliably (in lab environment). If you have a ticket opened, usually TAC support can assist to check how & why it is not working in your environment.
I see you have very detailed steps to reproduce, if somehow your case engineer already done checking all from FCT Diagnostic Result but no avail, may I suggest either below:
1. Join one of our lab PC to your EMS to reproduce & investigate the issue
2. Join one of your test machine to our lab EMS with your endpoint profile to reproduce & investigate the issue
This may help narrow down the root cause.
Created on 11-29-2022 01:44 AM Edited on 11-29-2022 01:45 AM
Hi and thanks for your answers!
How can we realize the point you mentioned -- Number 1: Join one of our lab PC to your EMS to reproduce & investigate the issue
You may open a ticket with us, and suggest this to your case engineer.
So after about 6 month of investigation with TAC, it boiled down to a bug, which will be fixed in 7.2.0 version of Forticlient.
I am really wondering that no one of you have got this issue....
Hey Menatwork,
Was your issue ever resolved? You are not alone; we have this problem as well. Our Forti ecosystem uses Client, EMS and Fortigates at the edge. When our users are behind the Fortigate which is connected to the DC with IPSEC, web filtering at the client does not work. When the client is on SSLVPN web filtering does not work. When the client is off network web filtering works. We are in the process of going to 7.2, hopefully it resolves these issues.
HTH
hi @bwill It was solved at the moment, when we upgraded to 7.2, but we have had numerous other troubles. Mainproblem is, that the Forticlient is not updating the av-defs as we expected. Some days it is unable to get the updates from the Fortinet-servers. The other day, there is a sandbox connection issue (Saas).
I have had tickts open, which never solved it (the update-issue). A few days after we opened the ticket about this, the updates worked again (out of nowhere). I was able to reproduce the problem at my "home-office-workplace" with completly different internet-access and clients. so I am sure the update-problem is "triggered" by fortinetservers (we connect from EU).
To be honest I will have to double check whether the webfilter of the Forticlient is still working reliable.
I will come back to you as soon as I have checked it.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.