Description:
This article provides step-by-step troubleshooting guidance for UTM Web Filtering issues where all websites are being allowed, including those configured with a "block" action. It helps identify configuration, licensing, connectivity, or software-related causes and provides guidance to restore proper web-filtering functionality.
Perform the following verification steps to identify and resolve Web Filtering issues on the SRX device:
Confirm that a valid Web-Filtering license is installed on the device:
show system license
Ensure the Web-Filtering license is present and has not expired.
Verify the connectivity and operational status of the ThreatSeeker Cloud service:
show security utm web-filtering status
If the TSC status is Up, review the UTM Web-Filtering configuration:
Useful commands:
show configuration security utmshow configuration security utm feature-profile web-filtering
Ensure the appropriate UTM policy is attached to the relevant security policy.
Example verification:
show configuration security policies
Confirm that the expected UTM policy is referenced under the applicable security policy rule.
Review Web-Filtering statistics and counters to determine whether requests are being processed by the UTM engine:
show security utm web-filtering statistics
Analyze the counters for:
If the configuration appears correct, review security logs for Web-Filtering events:
show log messages | match utm
or check configured security logging destinations for URL filtering actions and errors.
After completing the above checks, you should be able to determine whether the issue is related to: