Dear Concern,
I am visiting a website, but the page is not opening. In the forward logs, I see 'TCP reset from client' under 'action', and sometimes it shows 'accept'. The webpage says 'refused to connect'. How can resolve. I have FortiGate 201F firewall and firmware version is 7.0.10
If I check from another network, the webpage opens properly.
can anyone help me to resolve the issue
Solved! Go to Solution.
You can exempt that website by following this article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-a-static-URL-filter-feature-to-allow...
Regards,
Thank you for sharing the screenshot. It looks like you are using a wildcard url entry, but you have selected "Type: Simple". You may want to try changing the Type to Wildcard, or try removing the /* part of the url to keep it simple.
Test again, if the issue persists; then share some screenshots of the Policy that applies to the affected traffic in addition to the screenshots of the Web Filter which is applied to the same policy.
If you can go further into troubleshooting, then attaching a wireshark capture would help.
If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-6-7
Created on 08-12-2024 09:53 PM Edited on 08-12-2024 09:54 PM
Dear @Umer221 ,
According to you I have tried. But the issue still persist.
First, I checked the category of the URL, which was 'Category: General Interest - Personal' or 'sub-category: Education.' Then I went to the 'Security Profile,' checked the 'Web Filter' under 'Profile,' and found that the action for 'Category Based Filter' was set to 'Monitor,' not 'Block.' I also allowed this specific web page in the static URL filter.
Further I have tried to add the website in Custom Category which is called 'Custom 1' and the action is set to be Allow.
And yes, I am using both filters, 'Application Filter' and 'Web Filter,' in the IPv4 policy and This website or category is not blocked in Application Control.
And I have checked, this website is not blocked due to any other security check. It only fails to open when the web filter is enabled in the IPv4 policy through which the user's traffic passes.
Try using the following article to see if the issue is similar:
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Websites-with-allowed-categories-blo...
If you are using asterisk, you will need to set the type to wildcard
@Mirza_Asad2723 , Can you provide the browser error screenshot? Please also share the web filter logs for this connection.
Dear All,
After upgrading the firmware, the issue is resolved. The website is open while the web filter is selected as well.
Thanks to @pkumari @Umer221 @avneesh_ @HarshChavda @hbac
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.