Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Yavuz
New Contributor

Application control with blocked websites

Hi,

I came up with a strange issue, im using fortigate 300D Version 5.4 build 1011, the problem is as follows.

The client blocked storage sites, e.g. dropbox, google drive, etc, and also social websites, like facebook, instagram, three days back users were able to access those websites, when i checked in the application control log, those websites are shown as blocked, even though they're already been accessed.

i did block those websites from application control.

anyone faced same issue before?

Thanks

4 REPLIES 4
sophea89
New Contributor

Same thing happened here. I already blocked the youtube but somehow, certain user able to view video from youtube. Already check whether the user use the ultrasurf application, but she didnt. Any explanation from technical team? Currently i am using 1000D

Yavuz
New Contributor

It seems that application control is not working at all,

all the blocked applications are accessible, it's a strange behaviour,

when the users try to access those websites for the first time, they get the usual blocked page from fortigate, but after they attempt to refresh  the page few times, the page opens, and i doesn't block after that at all.

Thanks 

michaelbazy_FTNT

In my experience, most of the time, that would be because of an issue with HTTPS. Enabling deep scan can help. If not, maybe try to consider web filtering rather than application control (that is, if you want to block *all* website - app control is built to be a little more granular than that).

Last but not least, application control need signatures. Have you checked if you are up-to-date on that point?

I'm operating by "Crocker's Rules"
hmtay_FTNT

Hello Yavuz & sophea89,

 

Did you set the "Proxy" category to Block? Without looking into the configuration and logs, I cant tell you for sure what happened that caused the traffic to get through. VPNs are the most likely explanation for users bypassing the firewall. You need to keep the database up-to-date for the VPN signatures. If the problem keeps happening, can you open a ticket with the support team and we will look into it.

Labels
Top Kudoed Authors