Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Andrew3
New Contributor

FortiGate Web Filter Error: All FortiGuard servers failed to respond.

We started getting this Web Filter error recently and it's blocking traffic to places like apple.com and microsoft.com. I don't know why Fortiguard servers would be failing to respond now. We had to remove Web filtering due to this error. Any ideas?

 

Blocked Traffic: http://ocsp.apple.com/

http://crl3.digicert.com

http://ctldl.windowsupdate.com

 

Errors: Web Filter

Profile NamePublicRequest TypedirectDirectionoutgoingErrorall Fortiguard servers failed to respondMessageA rating error occurs

2 REPLIES 2
Yurisk
SuperUser
SuperUser

There can be few reasons, the one that FortiGuard servers all failed less likely of them. Yes, it happens that people report having issues with them but usually it passes quite fast.

Start with seeing the output diag debug rating

I wrote a post on debugging Fortigaurd servers connection, may be helpful https://yurisk.info/2021/02/21/failed-to-connect-to-fortiguard-servers-updated/ , and old but still valid https://yurisk.info/2009/06/19/failed-to-connect-to-fortiguard-servers/

 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
Andrew3
New Contributor

Thank you for this link. We were indeed on 6.4 and I just disabled Anycast. following your suggestions.

 

config system fortiguard

set fortiguard-anycast disable

set protocol udp

set port 8888

set sdns-server-ip 208.91.112.220 <-- IMPORTANT TO ADD THIS OR ANY OTHER FDN SERVER TO PREVENT DOWNTIME! end Previously, it was only showing 1 IP in the DI state. Now, it shows a full list of IPs and states other than DI. I'm hopeful that this resolves this issue but I will re-enable the policies and test again.

Labels
Top Kudoed Authors