I am having an issue with one particular web site that I can't figure out. When I try to access the site it just eventually times out. In my troubleshooting I tried accessing the same web site from a device in my DMZ to see if it could be a policy issue. The web site worked on the DMZ device.
I created a policy for my PC that allowed all traffic out to the Internet with no web filtering or IPS or anything. The web site did't work. I then thought about giving my PC an external IP address and assigning a policy allowing HTTP and HTTPS to the virtual IP of my PC and then the web site worked. As soon as I disable that policy the web site stops working.
I have done packet captures with that policy activated and deactivated. When it is activated I get the normal handshake and then I get a TCP Window Update from the web server and then my PC does the HTTP Get. When the policy is deactivated it does the normal handshake but then I get my PC issuing TCP ZeroWindowProbes and then it does a reset.
Is there something different with this web site (snopes.com) that could be causing this behavior? I don't know of any other web sites having an issue. Is there something else I can look at to figure out what is happening? I am using NAT from my internal network out to the Internet.
I believe the web site was working until recently. I don't know if it would have anything to do with it but I recently upgraded the firmware to v5.2.9 build736.
Any suggestions would be greatly appreciated. Thanks.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1749 | |
1114 | |
766 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.