Skip to main content
Sadhi_Jayz
Explorer
July 12, 2025
Question

Application Control Misidentifying DNS Traffic

  • July 12, 2025
  • 1 reply
  • 697 views

Hello Fortinet Community,

 

I'm encountering an issue with application control on my FortiGate 60F running firmware version 7.4.8M.

Scenario:

I created a WAN access policy that allows NTP, DNS, and PING services only.

 

4.png

 

Additionally, in the Application Control profile applied to this policy, I allowed only the following applications:

  1. NTP
  2. DNS
  3. PING

All other applications are set to block.

5.pngIssue:

 

Despite allowing DNS in the Application Control settings, I'm seeing legitimate DNS traffic being denied in the logs. This traffic is:

  • Port: 53 (UDP)
  • Destination: 8.8.8.8 (Google DNS)
  • Action: Denied
  • Detected Application: GitHub

1.png

 

2.png

 6.png

 

3.png

 

It appears the firewall is misclassifying some DNS traffic as the "GitHub" application, which is not allowed by the control policy, and thus it's being blocked.

 

What can I do to fix this without disabling Application Control Profile.

Any insights or suggestions would be greatly appreciated.

 

Thank You.

1 reply

AEK
SuperUser
SuperUser
July 14, 2025

Hi Sadhi

This my be app misclassification. Or can be some signature in this DNS traffic similar to GitHub app.

Does it happen only for DNS traffic from your "ubuntu-server"?

Is similar traffic from other hosts detected as GitHub app?

As a workaround try add GitHub app in the App Ctrl profile and see if it helps. Meanwhile you may open a ticket to get a clean fix.

AEK