Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
zeeorlando
New Contributor

Site only works with web filter disabled

I can only access a specific website when I disable the web filter.

 

The Fortigate 40F firewall doesn't display any message informing the blocked category. The website isn't placed in any category.

 

When I disable the web filter, I access it normally.

 

I've already placed the website in the Static URL filter, including Exempt, Block, Allow, and Monitor... but nothing happens. It doesn't block or allow.

 

I've also disabled the Fortiguard Category Basel filter, and nothing happens.

 

 

 

1 Solution
ozkanaltas
Valued Contributor III

Hello @zeeorlando ,

 

It seems your problem is not related to the web filter. 

 

You can follow that document for fixing ssl inspection issue.

 

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-How-to-fix-SSL-connection-is-blocked...

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW

View solution in original post

If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
12 REPLIES 12
ozkanaltas
Valued Contributor III

Hello @zeeorlando ,

 

Do you have a valid WebFilter license? 

 

Also, can your FortiGate reach FortiGuard IP addresses?

 

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
zeeorlando

Yes, I have a license, and FortiGuard is working perfectly...

Blocks websites that fall into the categories listed in the FortiGuard Category Based Filter.

Sheikh
Staff
Staff

Hello @zeeorlando 

 

What details do you see in the logs?

 

regards,

 

Sheikh

**If you come across a resolution, kindly show your appreciation by liking and accepting it, ensuring its accessibility for others**
zeeorlando

Here is a print of the log that appears to me

log de erro_.png

ozkanaltas
Valued Contributor III

Hello @zeeorlando ,

 

Can you also share web filter logs with us? 

 

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
zeeorlando

Hi, @ozkanaltas !

 

The log it displays for me is the one I posted above.

Unless I'm looking in the wrong place.

 

ozkanaltas
Valued Contributor III

Hi @zeeorlando ,

 

You should check the security event log for specific web filter logs

 

Log&Report->Security Event-> Web Filter logs

 

A similar forward traffic log to the one you sent should be in the web filter logs.

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
zeeorlando

It wasn't appearing in the web filter, but in the SSL log.

As shown in the image.

 

ssl error.png

Our firewall policy uses certificate inspection, as shown in the image below.

certificate inspection.png

ozkanaltas
Valued Contributor III

Hello @zeeorlando ,

 

It seems your problem is not related to the web filter. 

 

You can follow that document for fixing ssl inspection issue.

 

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-How-to-fix-SSL-connection-is-blocked...

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors