This is a newly configured Firewall. we try to enable the web filter in that. LAN pc's connect to the internet before enable the web filter. But after enable the web filter it's not connect to the internet. all configuration done correctly step by step.
1. Configure the LDAP server (Bind type - Reguler)
2. Configure the single sign on (Enable polling)
3. Configure the IPv4 policy
but after these steps LAN users can't access the internet.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
To be correct:
It does block the complete internet if it has no valid license or cannot reach the Fortiguard Servers to check.
Maybe you could use flow debug to see what your packets are doing on your fgt.
diag debug enable
diag debug flow filter <filter|list|?> (a "?" will have it show available filters , "list" will list the current filters)
diag debug flow show console enable (you want to see something on cli do you *g*)
diag debug flow trace start <numberofpackets> (stop will stop it again)
Mostly this gives you a clue what goes wrong with your packets...
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
I'm not expert of Fortigate but i had same trouble because my licence was down.
In our side licence is ok. Thank you for the help.
Hi,
Can FGT reach the Fortigaurdserver ? Can you try from FGT: #
exec ping service.fortiguard.net
Regards,
André Otta
Thank you André Otta.
But we resolve the problem with the help of Fortigate support.
Sometime, arrange the policy location almost work for me :)
Hello YASH1984,
The Web Filter blocks websites based upon categories. It doesn't block the entire internet, just pages that Fortinet has determined fall into specific categories, that you have chosen to block.
For this reason, I would think that your Web Filter is not the issue here. The difficulty reaching the internet is more likely found in the setup of your LDAP, SSO, or IPv4 Policy.
Those are the area's that I would focus my troubleshooting on.
I just updated our 240d cluster for 5.4.9 to 5.6.5 After the reboot the webfilter not worked more. There comes the message that no fortiguard server are avaible. I wait this night to see if there is some chage tomorrow. If not i will open a ticket. For the moment i disabled the webfilter what is not good but i not see any other option.
Regards
Marco
Do you have a green check by the Web Filter licenses on the Dashboard?
Can you: exec ping servicelfortiguard.net
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1547 | |
1031 | |
749 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.