Hello everyone,

First of all I would like to thank you all for welcoming me here.

I have an issue that I have recently noticed with my firewall, Fortigate. When accessing the web (any website) the following message pops up occasionally. I do not understand as sometimes I can access a site say now and when i try accessing the same site later cant access it;

You are not permitted to download the file “” because it is infected with the virus “unknown”. URL = http://www.xxx.xxx/ File quarantined as: . Fortiguard Legacy Redirect Client IP xxx User name: Group name:

Anyone to tell me what this all about and how it can be dealt with.

7 Spice ups

Well it seems to me 1 of a few things is happening:

  1. You are accessing a site that has a virus and the firewall is actually protecting you. Are you sure the site is safe? Is your browser infected and using a PROXY or has a HOST file changed on your PC… allowing your PC to go to infected sites vs. the real site?

  2. The antivirus engine of your fortinet is corrupted. Maybe the Fortinet AV plugin is broken or corrupted. Restart the fortinet. Remove and re-add the plugin. Call Fortinet support and see what they say… It may be a BUG in the Firmware? Update the firmware on the device too… maybe it will fix the issue.

Fortinet sometimes has things blocked it shouldn’t, I get a similar issue with their DNS service on some websites. Contact support and they’ll help you figure it out

Is your Fortigate up to date? Recent firmware, definitions, etc?

Is it a current model?

Thanks for your input. They really helped me finding the issue. The licensed FortiGuard Services -AV engine were expired and not up to date. I had to renew the license and update the AV/IPS engines