Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
technik
New Contributor

Fortigate - URL Filter - License

I currently have several sites, but only 1 test unit, which does not currently have a licencse. I have recently upgraded all units to mr2 patch 3 With the url filter enabled, the computer may eventually get to the page or timeout. If i disable the url filter in the firewall policy or in the web filter policy the internet works fine and all url blocks removed. I know the fortiguard web filter will not work in an unlicensed unit, but has the standard url filter now been added to the same scheme In the logs i get 2011-01-04 11:38:23 critical urlfilter 12552 service.fortiguard.net gethostbyname() failed. Everytime a web page is attempted to be accessed. Many thanks
3 REPLIES 3
Carl_Wallmark
Valued Contributor

Hi, That means it cannot resolve the fortiguard address, are your DNS settings correct ?

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
technik
New Contributor

everything works perfectly fine as long as i disable the url filter. If i enable the url filter, internet is opened up, and that error appears.
willem
New Contributor

If it tries to resolve the FortiGuard addresses, it is using them somewhere. And as you say yourself: without license that won' t work. If you' re only using the manual URL-filter, the FortiGate should not try to resolve to FortiGuard. Are you sure you don' t have FortiGuard URL-filtering enabled anymore in the UTM-profile? What you can always do, is enable the checkbox that allows browsing pages when a rating error occurs. That way the FortiGuard URL-filter is bypassed, because without license it will always give a rating error.
Willem __________________________________ FCNSP (Fortinet Certified Network Security Professional)
Willem __________________________________ FCNSP (Fortinet Certified Network Security Professional)
Labels
Top Kudoed Authors