Hi guys,

I have a problem with a fortigate 100f, when a websited is blocked, it is not showing the webfilter error message, it is only saying connection reset.

Investigating a little bit, i found out that disabling app control will do the trick.

Is there any way to have both tools enabled but showing the webfilter message when some site is blocked?

Thanks a lot!

17 Spice ups

We ran into that problem like 3 years ago and were told a fix was in the works.

That fix never came, even after outgrowing our old FortiGate and moving to a new one.

At the time, that was the latest firmware.

I no longer work there but we always kept the FortiGate up to date while I was, they just never fixed that.

Good luck.

2 Spice ups

I feel like if I recall, Application Control is processed before URL filtering (right before in flow mode and well before in proxy mode), so this makes logical sense on what you are describing. It’s blocking it via app control first thus no need to continue onto URL filtering. You can find which app it’s triggering in your logs, allow that app in your Application Control profile, then let the Web filter handle the website or sites however you need it to.

6 Spice ups

Yup, what @rogergaudet ​ said - URL filtering won’t happen until later, so your App. Control will scan that stuff first. But that could depend on a lot of stuff, too – mobile vs. local, SSL traffic, yada, yada. It’ll be tough to see “both” since those filtering apps are looking at different traffic.

3 Spice ups

We have Barracuda Firewalls and behaviour is same :slight_smile:

PR_CONNECT_RESET_ERROR

Well as long it is working and blocking thing needed to be blocked we are fine with it.