Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
graeme2015
New Contributor II

Web Filtering "monitor all" policy causes issues

Hi all,

 

Through FortiManager I pushed out the default "monitor all" web filtering policy to several small offices running FortiGate 60Ds (v5.2.3).  

A few offices were unable to browse, but getting an error saying something about a web rating timeout.

In the policy I then checked off the option "Allow Websites When a Rating Error Occurs" and then pushed the policy again.

This got rid of the error message, but I got complaints that sites were unable to browse or that browsing was extremely slow.  I tried the flow-monitor-all policy but this made no difference.  As soon as I removed the webfiltering profile from the policy, everything was back to normal.

 

Note that a lot of the sites that had complaints were remote sites running DSL connections (typically 3Mbps down, 512Kbps up).  So I'm thinking that during busy times that the bad connection to FortiGuard to get site ratings is causing delays in loading websites.

 

Has anyone experienced this behavior before and is there some kind of workaround to avoid it?

 

Thanks!

2 REPLIES 2
digimetrica
New Contributor

Me since today.

I had everything working then my customer switched to a new connectivity.

Then I started to have a lot of:

"

msg="A rating error occurs",error="rating timeout"

"

 

The fun thing is that this new connectivity is faster than the previous. I had to disable the web filter and check in some days. I am very angry at the moment

Sartuche24
New Contributor

I'm almost wondering if the problem is your Upload Speed thats causing a Web Rating lookup issue. You can use the FortiManager as a FortiGuard Server as well but if it's remote, then it won't solve your issue unless you have a dedicated connection back to your DC or wherever your FortiManager resides. I wonder if you could setup a traffic policy and setup a guarantee for connections to FortiGuard which may help with your timeout issues as you could prioritize traffic to FortiGuard. I would try this, having worked with smaller connections, this is what I would do to guarantee certain protocols or services have first stab at the connection.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors