I have some users that are occasionally getting blocked to streaming media sites, even though they are in a security group that gives access. And it is sporadic, some days they can access. I noted a pattern in the firewall logs: they do not have their username in the "User" column. Those unaffected by this do have their username listed. We are using FortiClient 5.6 on the computers, and FortiGate 300D (I don't know what version of software it is running).
Hello ehurst ,
1. Have you configured any web filter in forticlient.
1a) check the web site certificate .
2. Enable user name in logs using following command
FGT# config log setting FGT(setting)# set user-anonymize enable FGT(setting)# end
3. Check in SSL inspection this category is allowed and in web filter .
Verify in Application control signature is allowed.
4. You need to to packet capture or use the following debug command to check when its blocked .
FGT# di de url-filter src addr ----------> PC Address
FGT# di de application urlfilter -1
5. Check application control logs when its blocked. So you can check in which policy ID traffic is passing .
Regards,
Sudarsan Babu P
Regards,
Sudarsan Babu P
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.