Skip to main content
AlexFeren
New Member
April 19, 2017
Question

Fortigate Application Control "Dropbox" excludes web-based access?

  • April 19, 2017
  • 26 replies
  • 45455 views

Dropbox service can be accessed using a web browser or a host-based app.

Does Application Control "Dropbox" apply to traffic from web browser, host-based app or both?

    26 replies

    hmtay_FTNT
    Staff
    Staff
    April 19, 2017

    Hello AlexFeren,

     

    They cover both. However with the host-based app, you have to use the "Dropbox.Lan.Sync.Discovery.Protocol" signature too. The Download, Upload signatures work only on the web browser. Dropbox implements Certificate Pinning on its standalone applications. 

     

    HoMing

    AlexFeren
    AlexFerenAuthor
    New Member
    April 19, 2017
    Hi HoMing, thanks for reply. > They cover both. I don't see this at all. When I upload using browser, I don't see the the send/receive bandwidth numbers change in FortiAnalyzer's Fortiview's Top Applications' "app=Dropbox"; on the other hand, I do see the corresponding numbers change in Top Websites' "domain=dropbox.com". Can you explain the observation?
    hmtay_FTNT
    Staff
    Staff
    April 19, 2017

    Did you enable deep-inspection? Those signature require deep-inspection as they use HTTPS. You can do a quick check to see deep-inspection is enabled by looking at the Certificate of the session. If they are replaced with your certificate or the default FGT's then it's replaced. Otherwise, deep-inspection was not done.

    hmtay_FTNT
    Staff
    Staff
    April 21, 2017

    >>No! I don't see "require_ssl_di" in v5.2.10, observe:

     

    Sorry, the require_ssl_di syntax is only available in FortiOS 5.4 and above. 

     

    >>err..., your printout indicates value "No" for Dropbox application - doesn't this contradict your earlier allegation: 

     

    Dropbox does not require deep-inspection. Dropbox_Login, Dropbox_File.Upload and Dropbox_File.Download require deep-inspection.

     

    >>If you do comparison (after sorting), both are identical except for "SSL_TLSv1.2" entries. This means that "Dropbox" application signature excludes some traffic, even though everything is via same HTTPS protocol. Given that "require_ssl_di" is "No", can you explain this exclusion?

     

    Yes, it looks like a missed detection on that. I will look into it and get back to you in a bit. Sorry for the inconveniences.

     

    HoMing

     

    AlexFeren
    AlexFerenAuthor
    New Member
    April 28, 2017

    hmtay wrote:

    Yes, it looks like a missed detection on that. I will look into it and get back to you in a bit. Sorry for the inconveniences.

    Progress?

     

    hmtay_FTNT
    Staff
    Staff
    April 28, 2017

    Hello Alex, 

     

    The signature is in IPS Definition 10.127 and above.

    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!