Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
YASH1994
New Contributor

Web filter is not working properly in forti os 5.6?

This is a newly configured Firewall. we try to enable the web filter in that. LAN pc's connect to the internet before enable the web filter. But after enable the web filter it's not connect to the internet. all configuration done correctly step by step.

1. Configure the LDAP server (Bind type - Reguler)

2. Configure the single sign on (Enable polling)

3. Configure the IPv4 policy

 

but after these steps LAN users can't access the internet. 

1 Solution
sw2090
Honored Contributor

To be correct:

 

It does block the complete internet if it has no valid license or cannot reach the Fortiguard Servers to check.

 

Maybe you could use flow debug to see what your packets are doing on your fgt.

 

  diag debug enable

  diag debug flow filter <filter|list|?> (a "?" will have it show available filters , "list" will list the current filters)

  diag debug flow show console enable (you want to see something on cli do you *g*)

  diag debug flow trace start <numberofpackets> (stop will stop it again)

 

Mostly this gives you a clue what goes wrong with your packets...

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

View solution in original post

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
19 REPLIES 19
François
New Contributor III

I'm not expert of Fortigate but i had same trouble because my licence was down.

 

YASH1994

In our side licence is ok. Thank you for the help.

andreotta

Hi,

Can FGT reach the Fortigaurdserver ? Can you try from FGT: #

exec ping service.fortiguard.net

 

Regards,

André Otta

YASH1994

Thank you André Otta.

But we resolve the problem with the help of Fortigate support. 

SecurityPlus

What did FortiGate support recommend to solve this issue?
razer8388

Sometime, arrange the policy location almost work for me :)

McEathron
New Contributor

Hello YASH1984,

 

The Web Filter blocks websites based upon categories. It doesn't block the entire internet, just pages that Fortinet has determined fall into specific categories, that you have chosen to block.

 

For this reason, I would think that your Web Filter is not the issue here. The difficulty reaching the internet is more likely found in the setup of your LDAP, SSO, or IPv4 Policy.

 

Those are the area's that I would focus my troubleshooting on.

marco_d

I just updated our 240d cluster for 5.4.9 to 5.6.5 After the reboot the webfilter not worked more. There comes the message that no fortiguard server are avaible. I wait this night to see if there is some chage tomorrow. If not i will open a ticket. For the moment i disabled the webfilter what is not good but i not see any other option.

 

Regards

Marco

 

SecurityPlus

Do you have a green check by the Web Filter licenses on the Dashboard?

 

Can you: exec ping servicelfortiguard.net

Labels
Top Kudoed Authors