Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dime
New Contributor

Web filtering on Fortinet 90D

Hi all

We used to have a web filter in place for one of our clients which stopped them accessing YouTube etc. They have since decided they want this turned off which we have done from the web interface however, they are still unable to access YouTube. I'm new to looking at Firewalls etc and do we need to perform a restart in order for the Firewall to pick this change up? I've had a look within Application Control and video/audio is allowed so I'm a little bit confused as to where this is now being blocked from? Any help would be gratefully received.

Thanks

Josh

5 REPLIES 5
ede_pfau
SuperUser
SuperUser

hi,

 

there might be a chance that there are still old sessions continuing even after you've changed the webfilter setting. A reboot of the FGT will clear all sessions of course, and it will clear up possible memory issues etc. I'd try that first, preferably at night/low-traffic periods.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
dmcquade
New Contributor III

If the firewall is blocking access, there is unlikely to be any open sessions. I'd start by logging all traffic on the rule and review each security profile applied to the rule that allows this traffic. Chances are the forward traffic log will tell you something about what is causing the block. Are there any block messages displayed? If so, it should say somewhere on the page why it is being blocked. I.E. Webfiltering, Application Control, IPS, etc.

 

HTH

d

ede_pfau

and as usual, 'diag debug flow' is your friend...the end to speculation.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
bbrown
New Contributor

Wow and this goes unanswered. I have a similar problem with a 60E device.

ede_pfau

As with quite a few threads, the OP hasn't followed up. Perhaps we'll never know what his/her solution was.

 

It may be a config error, some other UTM (AppControl), routing, policies, wrong custom service,...working on such thin ice can be frustrating at times. And usually will not yield a solid answer ('shit in, shit out').

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors