Hi,
please refer to the screenshots - why is the FortiGate blocking legit HTTPS and HTTP traffic? The policy and the corresponding SDWAN rule should alllow everything. It just doesn't make any sense and the provided article is not helpful at all.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello
Please double-click on one log entry then share the shown details.
Hi smxko,
Added the column 'Threat Score' to confirm if it is populated with value 30.
I suggest you to run the commands below to understand why the traffic is being blocked.
diagnose debug reset
diagnose debug disable
diagnose debug console timestamp enable
diagnose debug flow filter clear
diagnose debug flow filter proto 6
diagnose debug flow filter addr x.x.x.x
diagnose debug flow filter port 443
diagnose debug flow show function-name enable
diagnose debug enable
diagnose debug flow trace start 500
### To disable the debug
diagnose debug disable
Post the output here.
Hi @smxko ,
Like what the KB article you referred to said, it is actually just traffic being blocked by the firewall policy.
Could you please share the FGT config and one raw log message with this issue?
Meanwhile, the debug flow outputs will help us more as well.
I found it - it's violation traffic that is logged when a user is connected but did not accept the disclaimer through the voucher portal. Took some time to put put one and one together :D But thanks for your quick help!
Hi,
config log threat-weight
set blocked-connection high >> see what you have set here..can you change it to other value other than high and see
end
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1711 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.