Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
BMDIT
New Contributor

www.msftconnecttest.com/redirect - Giving "Unknown" Error

Ladies and Gentlemen:

 

Got a problem that I suspect others have run into...

 

A user of mine keeps getting a "URL blocked by Forticlient" error when she tries to connect to the Internet at hotels or airport lounges.  The funny thing is, she's the only user getting that error.  I've got a couple of other users in the same circumstances that aren't getting it.

 

They're running FortiClient 6.0.8.  I found a thread (https://forum.fortinet.com/tm.aspx?m=165626) that talks about something similar, so I tried exporting the config, making the suggested change, and re-importing the config.  No change - it still doesn't work.

 

Any ideas?

 

Thanks!

 

Sean

4 REPLIES 4
tanr
Valued Contributor II

I'm not too familiar with FortiClient OffNet handling, but just wanted to make sure her client is set up to allow "Unrated"?  In case this is not a FortiGuard connection issue.

 

Is it possible her machine somehow got set to use a custom port for FortiGuard communication (other than UDP 8888)?  Or that she's got a local firewall that is blocking FortiGuard communications when off net?

BMDIT
New Contributor

tanr wrote:

I'm not too familiar with FortiClient OffNet handling, but just wanted to make sure her client is set up to allow "Unrated"?  In case this is not a FortiGuard connection issue.

 

Is it possible her machine somehow got set to use a custom port for FortiGuard communication (other than UDP 8888)?  Or that she's got a local firewall that is blocking FortiGuard communications when off net?

It's not telling her "Unrated", though.  It's telling her "Unknown".  And I've got the URL (msftconnecttest.com) flagged as an allowed site on our FortiGate.  The entire error is as follows:

 

"FortiClient has been configured to block unrated URLs.

This URL was categorized as unrated because the FortiGuard URL rating service is inaccessible."

 

I took a look at the FortiClient config and can't see where it says to allow unrated URLs.  Any pointers?  Or is this something that I need to configure on the FortiGate, have her make a successful connection, and then try it?

 

Thanks!

tanr
Valued Contributor II

Are you using EMS to manage the FortiClient endpoints, or just doing it from the FortiGate? 

 

If you're just managing it from the FortiGate without EMS then I think you can look at the FortiClient Compliance Profile that's getting applied and see which web filter profile it's using.  Verify that the web filter profile has the Unrated category allowed and "Allow websites when a rating error occurs" checked.

 

BMDIT
New Contributor

Just managing it from the FortiGate without EMS.

 

I took a look at the FortiClient Compliance Profile that's being applied, and there's nothing in there about a web filter profile (the FortiGate's running 6.0.8).  However, I did notice that she has an entry in User Definition when no other FortiClient user does.  I think it might be related to that...

Labels
Top Kudoed Authors