Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Mirza_Asad2723
New Contributor II

Webpage not open "TCP reset from client"

Dear Concern,

 

I am visiting a website, but the page is not opening. In the forward logs, I see 'TCP reset from client' under 'action', and sometimes it shows 'accept'. The webpage says 'refused to connect'. How can resolve. I have FortiGate 201F firewall and firmware version is 7.0.10

 

If I check from another network, the webpage opens properly.

 

can anyone help me to resolve the issue

1 Solution
16 REPLIES 16
Umer221

@Mirza_Asad2723 

 

Thank you for sharing the screenshot. It looks like you are using a wildcard url entry, but you have selected "Type: Simple". You may want to try changing the Type to Wildcard, or try removing the /* part of the url to keep it simple.

Test again, if the issue persists; then share some screenshots of the Policy that applies to the affected traffic in addition to the screenshots of the Web Filter which is applied to the same policy.

 

If you can go further into troubleshooting, then attaching a wireshark capture would help.

 

If you have found a solution, please like and accept it to make it easily accessible to others.

NSE 4-6-7

Mirza_Asad2723

Dear @Umer221 ,

 

According to you I have tried. But the issue still persist.

 

Capture04.JPG

 

First, I checked the category of the URL, which was 'Category: General Interest - Personal' or 'sub-category: Education.' Then I went to the 'Security Profile,' checked the 'Web Filter' under 'Profile,' and found that the action for 'Category Based Filter' was set to 'Monitor,' not 'Block.' I also allowed this specific web page in the static URL filter.

Further I have tried to add the website in Custom Category which is called 'Custom 1' and the action is set to be Allow. 

And yes, I am using both filters, 'Application Filter' and 'Web Filter,' in the IPv4 policy and This website or category is not blocked in Application Control.

And I have checked, this website is not blocked due to any other security check. It only fails to open when the web filter is enabled in the IPv4 policy through which the user's traffic passes.

 

Umer221
avneesh_

If you are using asterisk, you will need to set the type to wildcard

Mirza_Asad2723

Dear @avneesh_ 

 

Yes, I tried but the issue still persist.

pkumari

@Mirza_Asad2723 , Can you provide the browser error screenshot?  Please also share the web filter logs for this connection.

Mirza_Asad2723
New Contributor II

Dear All,

 

After upgrading the firmware, the issue is resolved. The website is open while the web filter is selected as well.

 

Thanks to @pkumari @Umer221 @avneesh_ @HarshChavda @hbac 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors