Regards, Paulo Raponi
service is http action accept, web filter checked and test profle selected I get timeouts on EVERYTHING with it enabled from the test host.I assume you have enabled NAT on that fw policy? If FortiGuard Categories is enabled in the web filter profile If so I assume your fgt has a valid FortiGuard subscription? Can you confirm the correct URL filter list is assigned to the web filter profile? How did you craft the actual URL entry (as a wildcard or regex)? Do you have an app sensor enabled on that fw policy? If so check to see the site is not being blocked by it.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
ORIGINAL: pcraponi Move to the last MR3 version (patch14) and try againum....no? unless its a known bug for the version I am on that doesnt make sense. if its a known issue I' m happy to move to a newer patch though
ORIGINAL: Dave Hall I assume you have enabled NAT on that fw policy? If FortiGuard Categories is enabled in the web filter profile If so I assume your fgt has a valid FortiGuard subscription? Can you confirm the correct URL filter list is assigned to the web filter profile? How did you craft the actual URL entry (as a wildcard or regex)? Do you have an app sensor enabled on that fw policy? If so check to see the site is not being blocked by it.I' ll double check that I remember to check the box for NAT fortiguard is up to date, I checked the URL filter numerous times, its set as a simple block to the website with the domain name and then .com no app sensor enabled
ORIGINAL: dmmillr1The onus is on you to determine if a newer patch has resolved your issue. We' re not going to do your homework. (at least I' m not!)ORIGINAL: pcraponi Move to the last MR3 version (patch14) and try againum....no? unless its a known bug for the version I am on that doesnt make sense. if its a known issue I' m happy to move to a newer patch though
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
ORIGINAL: dmmillr1 I' ll double check that I remember to check the box for NAT fortiguard is up to date, I checked the URL filter numerous times, its set as a simple block to the website with the domain name and then .com no app sensor enabledInstead of describing the problem, actual script code and/or a screenshot would be better. (You also did not indicate if the correct URL filter list is tied to the web filter profile assigned to the test computer.) Off the top of my head I would say check the submask on the fw object for your test computer -- it should be /32. If you have utm logging enabled it should indicate why the test computer was blocked. Again, script code and/or screenshot would help (san any identifying outside IP addresses).
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
ORIGINAL: rwpatterson The onus is on you to determine if a newer patch has resolved your issue. We' re not going to do your homework. (at least I' m not!)sorry wasn' t inferring you needed to. I haven' t had time to get into the release notes, as this is for a part time consulting gig(previous FT employer) and I need to get the main support password I just don' t think that blindly code upgrading or rebooting a box to try and fix a problem is the first thing to try :)
ORIGINAL: Dave Hall Instead of describing the problem, actual script code and/or a screenshot would be better. (You also did not indicate if the correct URL filter list is tied to the web filter profile assigned to the test computer.) Off the top of my head I would say check the submask on the fw object for your test computer -- it should be /32. If you have utm logging enabled it should indicate why the test computer was blocked. Again, script code and/or screenshot would help (san any identifying outside IP addresses).Ill get a screen up for ya, I did check and the correct URL filter is applied, but I can get screens of all of it I will post the logs as well, not digging into them was a silly mistake, but in my defense aka excuse....my 5 month old stopped sleeping at night this week and I' m getting pretty tired :p
User | Count |
---|---|
140 | |
70 | |
64 | |
42 | |
37 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.