Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
womble84
New Contributor

Whatsapp

I had a client request whatsapp be opened up temporarily during this lockdown period while some of them are in the office and communicating via the app.  They had it blocked and opened it again and ensured the application policy was enabled ok and confirmed with the client it was indeed working fine.

 

The next day it stopped working, disabled the policy and re-enabled it again and working again, next day not working.  I created a new policy with the ports whatsapp uses and tried that and working and again today not working. 

 

What is causing this to stop every day?

1 Solution
Dave_Hall
Honored Contributor

Hi Simon.

 

We would need more information on the issue. 

 

First what fgt firewall is the client using and how are you "allowing" the whatapp through? 

 

Is it a combination of web filter/url filer/App sensor rules on a firewall policy? 

 

Is this firewall policy enabled all the time or is there a set scheduled?

 

Have you used FortiView to drill down to the indivudal device sessions to monitor what is happening when a device attempts to connect via whatapps?

 

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

View solution in original post

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
2 REPLIES 2
Dave_Hall
Honored Contributor

Hi Simon.

 

We would need more information on the issue. 

 

First what fgt firewall is the client using and how are you "allowing" the whatapp through? 

 

Is it a combination of web filter/url filer/App sensor rules on a firewall policy? 

 

Is this firewall policy enabled all the time or is there a set scheduled?

 

Have you used FortiView to drill down to the indivudal device sessions to monitor what is happening when a device attempts to connect via whatapps?

 

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
ede_pfau

For WA access, you only need to open a couple of ports/tcp) as documented by whatsapp.com.

I've used that myself and had no problems at all.

Please check the policy used by this traffic does not use any webfilter, application control or DNS filter.

Stopping traffic after a (long) time span points to a schedule in place. Be sure you don't use any here.

 

Anyway, if your FGT really blocks this application then it should log a security event when doing so. Check the logs.

 


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors