Skip to main content
N_W
Explorer
March 15, 2024
Question

Forti Rule and Application İssue

  • March 15, 2024
  • 1 reply
  • 1552 views

Hello, I have a FortiGate device running on version 7.2.7 in proxy-based mode. I noticed that despite some users having WhatsApp allowed in their respective policies, they are unable to perform file transfers intermittently. While some users can occasionally perform transfers, others cannot, even though they are subject to the same policy. Upon reviewing logs, I observed that some users get stuck at the "File_Transfer" stage while others do not, despite being under the same rule. This situation has left me confused, and I would appreciate your insights. Thank you.

whatsapp-rule.PNG

whatsapp-log-allow.PNG

whatsapp-log-deny.PNG

whatsapp.PNG

    

1 reply

ozkanaltas
Valued Contributor III
March 15, 2024

Hello @N_W ,

 

Can you add the signature "WhatsApp_Web_File.Upload" and "WhatsApp_File.Transfer" to your app control profile? In my opinion, sometimes FortiGate misses some package about upload. Because of that, some users can send files via WhatsApp some users can't.

 

I think it will work once you do this.

 

image.png

N_W
N_WAuthor
Explorer
March 15, 2024

Hello, thank you for getting back. Since I'm using NGFW MODE: Proxy-based, I don't have Application Control in my Security Profile. So, when writing rules, only the Application comes under the Service, and unfortunately, nothing other than WhatsApp and WhatsApp_Web appears there. Just to let you know. Have a good day

whatsapp-----.PNG

 

ozkanaltas
Valued Contributor III
March 15, 2024

Hello @N_W

 

You are right, cannot add these signatures directly to the policy. But you can create an application group in the "Policy&Object->Application" menu with these signatures. 

 

image.png

 

After that configuration, you can use this group in the policy. 

 

image.png