Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Nascimento
New Contributor II

ERR_EMPTY_RESPONSE only using Google Chrome accessing WhatsappWeb, Instagram and Facebook

Hey guys!
Problem: Users in the company receiving message "ERR_EMPTY_RESPONSE" when using Google Chrome to access WhatsappWeb, Instagram and Facebook. Chrome is the company's default browser. We did tests using Microsoft Edge and everything works normally, the problem is with Chrome. Clear browser caches, restore settings, reinstall Chrome, clear DNS cache, etc. Nothing our field service did worked, but it works with Edge.
I created a rule granting full access for one computer (without asking for authentication and without any filters), everything worked in Chrome. In other words, there is some combination of access rule + Chrome + websites (Whatsapp, Facebook and Instagram) that is blocking this access on Fortigate, but that does not harm the Edge browser. Has anyone here dealt with a similar problem?

JSN
JSN
12 REPLIES 12
hbac
Staff
Staff

Hi @Nascimento,

 

Are you using webfilter and proxy based policy? Can you check Web Filter event logs? Do you see this error this error "unknown content-encoding detected and blocked"?

 

Regards, 

Nascimento
New Contributor II

Thanks for your response. I disabled Application Control and IPS in the Policy that allows access and so the access works. Either with IPS enabled or Application Control enabled, access stops working only for Chrome accessing Instagram, Facebook and WhatsAppWeb. So I still don't understand what is really happening.

JSN
JSN
smaruvala

Hi,

 

- Was this working fine before? Were there any changes in the Firewall configuration? 

- What is the Chrome version you are using?

- In the Application Control are you blocking any application?

- Could you share the configuration of the Policy?

 

Regards,

Shiva

Nascimento

Yes it was working fine before. I upgraded the Fortigate to FortiOS v6.4.15 build2095 (GA). The Chrome is on version 122.0.6261.69 (Official Version) 64-bit. In Application Control I'm not blocking any application.

JSN
JSN
V_Sa
New Contributor

I have the same problem here.
It works with Edge though, very strange!

YoannP
New Contributor

Same problem for me.

In proxy based policy, with IPS and App control I can't access FB and Instagram when I use Chrome.
It works when I use Firefox.

No problem in flow based policy

FGT-80F v7.4.3

GonA
New Contributor

Same problem for me.
However, if I disable Zstd encoding on Chrome, it works.

-> chrome://flags/#enable-zstd-content-encoding <-

Does Fortigate support this type of encoding in proxy based policy?

V_Sa
New Contributor

Thanks for your tip!

I have now switched off zstd via GPO.

hbac

Hi @GonA,

 

Zstd is not supported as of now. It is being worked on. You can disable zstd on Chrome or set "unknown-content-encoding" to "inspect". 

 

# config firewall profile-protocol-options

# edit <> 

# config http

# set unknown-content-encoding inspect

# end 

 

For more information, please refer to https://community.fortinet.com/t5/FortiGate/Technical-Tip-usage-of-quot-unknown-content-encoding-quo...

 

Regards, 

Labels
Top Kudoed Authors