A network administrator notices that HTTP traffic to a specific website is being blocked by the web filter profile, but the website is categorized as 'General – Personal' in FortiGuard, which is allowed. What could cause this block?
Trap 1: The web filter profile has an incorrect FortiGuard category override
A FortiGuard category override changes the action for an entire category, not for a single website. If the website's category is permitted by default and the override is not explicitly set to block, it cannot be responsible for blocking that URL. Moreover, any category-based override would affect all sites in that category, not a single specific website, which contradicts the symptom described.
Trap 2: The antivirus profile is blocking the website
Antivirus profiles in FortiOS inspect file content and block malware downloads, not individual websites by URL or domain. The AV engine cannot make an allow/block decision based on the requested hostname; it only acts after data reaches the FortiGate. If the site simply served HTML, the AV profile would have no basis to block the HTTP request itself, so this is not a plausible cause.
Trap 3: DNS filter is blocking the domain
A DNS filter blocks domains by intercepting DNS queries and dropping the resolution, so the client receives no IP address and the HTTP request never reaches the FortiGate's web filter. If the DNS filter were blocking the domain, the user would see a DNS resolution failure rather than a web-filter block page. The fact that the issue is observed in HTTP traffic to a specific site suggests that the request was successfully routed to the web filter, ruling out DNS filtering as the cause.
- A
The web filter profile has an incorrect FortiGuard category override
Why it fails: A FortiGuard category override changes the action for an entire category, not for a single website. If the website's category is permitted by default and the override is not explicitly set to block, it cannot be responsible for blocking that URL. Moreover, any category-based override would affect all sites in that category, not a single specific website, which contradicts the symptom described.
- B
The antivirus profile is blocking the website
Why it fails: Antivirus profiles in FortiOS inspect file content and block malware downloads, not individual websites by URL or domain. The AV engine cannot make an allow/block decision based on the requested hostname; it only acts after data reaches the FortiGate. If the site simply served HTML, the AV profile would have no basis to block the HTTP request itself, so this is not a plausible cause.
- C
A URL filter entry is blocking the specific website
URL filter entries are local, rule-based patterns evaluated before FortiGuard category lookup. If a block entry matches the specific domain or URL, the session is dropped immediately, regardless of the category's default action. This is why a single website can be blocked while other sites in the same FortiGuard category remain accessible, as described in the scenario.
- D
DNS filter is blocking the domain
Why it fails: A DNS filter blocks domains by intercepting DNS queries and dropping the resolution, so the client receives no IP address and the HTTP request never reaches the FortiGate's web filter. If the DNS filter were blocking the domain, the user would see a DNS resolution failure rather than a web-filter block page. The fact that the issue is observed in HTTP traffic to a specific site suggests that the request was successfully routed to the web filter, ruling out DNS filtering as the cause.