Hello all,
today my 240d cluster was crashing. I had over the last ours 340.000 blocked sessions just for play.google.com
Its okay for me that its blocked cause i have in the webfilter profile software and freeware downoad blocked. But i
am wondering what made this high amount of sessions. Was google doing some or do i have a virus in the network
that asked the clients to download from play.google.com ?
The firewall was than out of memory and it was needed to reload the cluster to get the funtktion back,
If somebody can tell me what possible happend would be great
Regards
Marco
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
What do your webfilter logs show (Log & Report > Web Filter)? You should be able to filter the logs to see the sources and other details.
I have a nat device between fortigate and user network so i just see one IP that comes from user network. These sessions are blocked cause of the webfilter policy that blocks freware and software downloads. I checked in an other firewall that more than 200 user ip are accessing play.google.com but always the same ip 216.58.206.14 i thought that behinf play.google.com is a CDN that changes the ip addresses depending on the load.
BR
Marco
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.