Skip to main content
ISOffice
New Member
December 13, 2013
Question

Application Sensor Not Working

  • December 13, 2013
  • 8 replies
  • 19763 views
Hi All, We have a 100D Cluster (v5.0 GA Patch 3) running active-active at the edge of our wireless network. Our Internet policy is pretty standard with an Anti-Virus Profile (Flow-based), a Webfilter Profile (Flow-based), an IPS Sensor Profile and an Application Control policy applied to it. The Wefilter portion appears to work OK, that is, categories of websites we want blocked are indeed blocked. However, the Application Control policy appears to have no effect whatsoever. I have configured it to block all P2P applications, yet I can still use Vuze to download files. Also, the Application Name column in the Forward Logs is populated with ' Unknown' (with the exception of DNS). Occasionally (and quite rarely, I might add) ' HTTP.BROWSER' will appear in the Forward Logs under Application Name. Has anyone any idea as to what may be occuring here, am I missing something totally obvious? Any assistance would be much appreciated. Many thanks, JP

    8 replies

    joco_ph
    New Member
    December 13, 2013
    column in
    have the same issue on a standalone FG100D.
    wcente
    New Member
    December 18, 2013
    Same with 505 on FGT60C
    netmin
    New Member
    December 19, 2013
    The default application detection rate on our 5.0.5 test box appears to be quite substandard as well. After having enabled logging for specified, other and unknown applications it does only occasionally show entries like Windows updates, McAfee updates, Symantec updates, browsers, etc., etc. A little bit of tweaking ' config ips global' seems to have improved this for now, but this is still to be monitored for other applications and performance. Currently we use: config ips global set algorithm high (default: engine-pick) set database extended (default: regular) set ignore-session-bytes 524288 (default should be: 204800) set hardware-accel-mode cp-only (default: engine-pick) set session-limit-mode accurate (default: heuristic) Modification depends on the used hardware and requirements of course.
    ISOffice
    ISOfficeAuthor
    New Member
    April 23, 2014
    For info, We have just upgraded the 100D Cluster to Version 5.0 Patch Release 7 (Build 4429). This appears to have gone some way to resolving our issue. Applications are now being correctly identified and blocked where policy dictates.
    Dipen
    New Member
    June 22, 2014
    For general browsing the application name will be unknown in Traffic Logs. Have you tried blocking " Social Media" and check if Facebook etc are actually blocked. Suggestions...Please go for FortiOS 5.2 where Block-page [replacement=message] has been introduced in Application Control as well fantastic for me.
    Jirka1
    Explorer II
    September 5, 2014
    Hi all, we use Fortigate 100D (v5.0, build 4429 (GA) and we also have a problem with correct detection applications. In Policy we use default-list, which is set monitoring all known and unknow applications. We still have in the log as 98% of applications " unknow" . Sometimes it detects DNS, but only sometimes. Does anyone have any idea? Thank you.
    config application list      edit " default"           set comment " monitor all applications"           set extended-utm-log enable          set log enable
    config firewall policy      edit 25          set srcintf " IPsec_zone"           set dstintf " INET"           set srcaddr " Branch1-LAN"           set dstaddr " all"           set action accept          set schedule " always"           set service " ALL"           set utm-status enable          set comments " Branch1 to INET"           set webfilter-profile " default"           set ips-sensor " default"           set application-list " default"           set profile-protocol-options " default"           set nat enable          set ippool enable          set poolname " Branch1"       next  end
    Dipen
    New Member
    September 6, 2014
    config application list edit " default" set comment " monitor all applications" set extended-utm-log enable set log enable config firewall policy edit 25 set srcintf " IPsec_zone" set dstintf " INET"
    As told earlier for generic Browsing the application name is detected as Unknown
    Nihas
    New Member
    September 8, 2014
    yet I can still use Vuze to download files.
    It seems they have not yet included the service in application signature. They are keep updating application signatures and whenever you get IPS databse updated, it will be available for your use. you can create a custom application signature if you have details. Or you can ask Fortiguard team to make it done ( globally) through the below link http://www.fortiguard.com/encyclopedia/applications/appform.html
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!