Skip to main content
darre
New Member
October 3, 2024
Question

App ctrl - Block applications detected on non-default ports

  • October 3, 2024
  • 6 replies
  • 6094 views

Hi,

I have configured an Application Control profile and applied on a firewall policy. The application control profile have "block applications detected on non-default ports" enabled. However, when I run Telnet on other ports than 23 the traffic is allowed and it's also detected as application Telnet according to the logs on FortiGate.
I have verified that the traffic is hitting the correct firewall policy.

I am running FortiOS 7.4.5.

Please see my configuration on attached pictures.
What am I doing wrong? Shouldn't this traffic be blocked?

image.pngimage.pngimage.png



6 replies

kmohan
Staff
Staff
October 3, 2024

Hi darre,

Application Filter>>You have create with Telnet with Action Monitor, and this Telnet is relate Remote access category.

If you set action as Monitor, it will by pass traffic from the FGT, it will not block.

 

Only, if set action as block, then it will deny the traffic from the FGT.

VictorSB
New Member
November 13, 2024

I had the same issue with Telnet testing over port 443 - Traffic explictly identified application telnet and some times as "Web Browser" - and none of them were blocked.

 

Did you find any answer about this topic?

pminarik
Staff
Staff
November 14, 2024

Telnet is potentially extremely generic. Depending on the exact implementation, it may just generate a TCP handshake, with no data unless you start typing something in. And if you do, the detection will depend on what exactly you're pushing through the session.

 

This will absolutely need an analysis of a pcap of the traffic session.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!