Hi Experts,
we are having problem on the enhanced webfiltering. everything is configured right(i hope so) but all the websites that should be blocked based on the category list from the EWF profile that we created are getting permited. based from the output of "show security utm web-filtering statistics" all sites are getting permitted because "Fallback timeout" see output below.
here are the config of EWF and output of "show security utm web-filtering statistics"
set security utm utm-policy enhanced_webfiltering web-filtering http-profile BLOCKED_SITES
set security utm utm-policy enhanced_webfiltering traffic-options sessions-per-client over-limit log-and-permit
set security utm feature-profile web-filtering url-whitelist Whitelist_02-08-2017
set security utm feature-profile web-filtering url-blacklist Blacklist_02-08-2017
set security utm feature-profile web-filtering juniper-enhanced cache timeout 1800
set security utm feature-profile web-filtering juniper-enhanced cache size 500
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Whitelist_02-08-2017 action permit
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Blacklist_02-08-2017 action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Government action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Religion action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Society_and_Lifestyles action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Weapons action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Violence action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Vehicles action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Travel action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Tasteless action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Sports action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Racism_and_Hate action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Militancy_and_Extremist action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Job_Search action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Gambling action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Drugs action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Abortion action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Social_Web_Facebook action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Social_Web_Linkedin action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Social_Web_Youtube action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Cultural_Institutions action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_MP3_and_Audio_Download_Services action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Military action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Nudity action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Sex action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Traditional_Religions action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Proxy_Avoidance action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Non_Traditional_Religions_and_Occult_an action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Hacking action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Personals_and_Dating action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Abused_Drugs action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Alcohol_and_Tobacco action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Gay_or_Lesbian_or_Bisexual_Interest action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Prescribed_Medications action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Adult_Material action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Adult_Content action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Blogs_and_Personal_Sites action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Lingerie_and_Swimsuit action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Sex_Education action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category block_facebook action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Illegal_or_Questionable action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Block_ipligence action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Advanced_Malware_Command_and_Control action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Advanced_Malware_Payloads action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Bot_Networks action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Compromised_Websites action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Keyloggers action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Malicious_Embedded_Link action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Malicious_Embedded_iFrame action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Malicious_Web_Sites action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Peer_to_Peer_File_Sharing action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Phishing_and_Other_Frauds action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Potentially_Unwanted_Software action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Suspicious_Embedded_Link action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Suspicious_Content action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES category Enhanced_Potentially_Damaging_Content action block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES site-reputation-action very-safe permit
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES site-reputation-action moderately-safe permit
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES site-reputation-action fairly-safe permit
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES site-reputation-action suspicious permit
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES site-reputation-action harmful permit
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES fallback-settings default log-and-permit
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES fallback-settings server-connectivity log-and-permit
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES fallback-settings timeout log-and-permit
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES fallback-settings too-many-requests log-and-permit
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES default block
set security utm feature-profile web-filtering juniper-enhanced profile BLOCKED_SITES custom-block-message Test
set security policies from-zone trust to-zone untrust policy SECPOL_BLOCKED_SITES then permit application-services utm-policy enhanced_webfiltering
root# run show security utm web-filtering statistics
UTM web-filtering statistics:
Total requests: 311698
white list hit: 0
Black list hit: 0
No license permit: 0
Queries to server: 0
Server reply permit: 0
Server reply block: 0
Server reply quarantine: 0
Server reply quarantine block: 0
Server reply quarantine permit: 0
Custom category permit: 0
Custom category block: 0
Custom category quarantine: 0
Custom category qurantine block: 0
Custom category quarantine permit: 0
Site reputation permit: 0
Site reputation block: 0
Site reputation quarantine: 0
Site reputation quarantine block: 0
Site reputation quarantine permit: 0
Site reputation by Category 0
Site reputation by Global 0
Cache hit permit: 0
Cache hit block: 0
Cache hit quarantine: 0
Cache hit quarantine block: 0
Cache hit quarantine permit: 0
Safe-search redirect: 0
Web-filtering sessions in total: 64000
Web-filtering sessions in use: 22
Fallback: log-and-permit block
Default 0 0
Timeout 306452 3469
Connectivity 0 0
Too-many-requests 0 0