DISCLAIMER: I'm new to firewall administration and FortiGate products as a whole.
Our users are unable to access any state government websites, ending with the state domain name, hawaii.gov. We don't have any rules explicitly blocking these sites or this domain, and I have added rules in the FortiGate to explicitly allow them. Here are the steps I've taken so far:
[ul]None of this would allow us to get to the website, until I specifically added the IP address and DNS name of the website in the computer's hosts file.
What am I missing?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Sounds like DNS filter is blocking it, not web filtering. To start, create a simple policy with the wildcard FQDN (assuming 6.2.2 or above) as destination then service: DNS, HTTP/HTTPS, and allow for the action without any protection profile. Place it at the top of the policies. Make sure this works.
Then you can start adding those DNS filter then Web filter and others, one by one. With that way, you can know what is causing the block, and go back one step then tweak the profile.
Or, more direct method is to run "flow debug" by searching how to do it on the internet, or in the forum, to see the direct cause of blocking.
agreed and i would double check the fqdn list
e,g. diag firewall fqdn list | grep haw
Ken Felix
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1072 | |
751 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.