QuestionQ15

Security profiles

While investigating a FortiGate web-filtering problem, users state that they cannot reach any websites, although those sites are not explicitly denied by any web-filter profiles applied to firewall policies.

What are the three most likely causes of this behavior?

Choose three
  • A The webfilter-force-off setting has been enabled under config system fortiguard.
  • B The FortiGuard Web Filtering license has expired, causing FortiGate to apply the default block action.
  • C The SSL/TLS deep inspection was configured but the browsers do not have the FortiGate certificate installed.
  • D The web filter cache has been cleared causing all websites to take longer to be rated.
  • E The DNS server is unreachable, preventing URL resolution.
Explanation

An unavailable or expired FortiGuard Web Filtering subscription can prevent URL categorization and lead to access being denied under the configured default behavior. SSL/TLS deep inspection re-signs HTTPS certificates with the FortiGate CA, so browsers that do not trust that CA can reject HTTPS connections. An unreachable DNS server prevents users from resolving website hostnames, so sites cannot be reached. The webfilter-force-off setting instead disables FortiGuard web filtering, and clearing the web-filter cache causes fresh rating lookups rather than inherently blocking every site.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!