Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dan_newcombe
New Contributor

Forticlient stopping all SSL/TLS traffic

We're seeing an odd problem that seems to come and go.  Users are on Forticlient 5.6.5, and we're on Fortigate 5.6.5.  Occasionally, some users will not be able to visit any SSL/TLS sites.  Doesn't matter what browser.  They receive an ERR_SSL_PROTOCOL_ERROR.  All sorts of remedies online such as checking time, reinstall this and that, etc.  Basically a generic message for something went bad.

 

What we have found is if we disconnect the Forticlient from the Fortigate, go to the web site, and then reconnect to the fortigate (or completely stop/start Forticlient or reboot), the issue goes away.  We've had a handful of issues with this in the last two days, and then we'll go for a couple of months without seeing it.

 

Anyone else see this before?  Not even sure where to begin trying to track this down.  Nothing obvious on the Fortigate under Web Filter or Client logs.

2 REPLIES 2
SteveG
Contributor III

We've been using FC for a few years and haven't noticed this. Is there anything in the Fortigate logs? Do you have web filtering enabled on FC as if you don't then it's more likely to be the FG blocking the traffic.

 

First thing I'd try is upgrading FC to 6.0.5 and see if that makes any difference.

dan_newcombe

I  did not notice anything in the Fortigate logs that stood out.  We do have web filtering enabled on FC.   I suppose to start to narrow this down, we could take a problematic client and just disable web filtering on it to see if that step helps.  At least we'd know where to start digging.

 

I could believe it being web filtering.  On my desktop, I have web filtering turned off.  On the fortigate, I am in a bypass group.  However, my local Forticlient still occasionally blocks stuff, in particular for Newly Observed Domain, even though filtering is turned off, and even if I did have the main profile on the fortigate, that profile is set to allow that traffic.   

 

I think 6.0.5 will be a step to take soon - 5.6 is having some weird quirks for us.

Labels
Top Kudoed Authors