Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Mbutler522010
New Contributor

blocking and not blocking, website confusion

I am really trying to understand what I see in the logs. The screenshot shows a highlighted line (8:32:51) where a user attempting to get to "216.58.193.110" and then in parenthesis it says "connectivitycheck.android.com"

 

The attempt is blocked and the filter details say it was actually URL "play.google.com/"

 

Then 4 seconds later (8:32:55) it shows the exact same entry, but this time it is allowed and the webfilter says the URL was "clients5.google.com/"

 

How am I supposed to know what is going on?

2 REPLIES 2
rwpatterson
Valued Contributor III

Doing a bit of legwork, 216.58.217.110 resolves to iad23s42-in-f110.1e100.net. From that alone, I would guess that this is a data storage/download server site that hosts multiple aliases. One of those aliases is connectivitycheck.android.com. I would also wager a guess that the other URL is disallowed from that same IP address by DNS name, but the IP is allowed.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Mbutler522010

Thanks Bob!

that sure makes it difficult to figure out what is going on though

Labels
Top Kudoed Authors