Skip to main content
1mm
Explorer III
July 26, 2023
Question

Fortigate SSH

  • July 26, 2023
  • 14 replies
  • 7292 views

Hello,

 

We have one Ubuntu Server there we have enabled SSH and now I'm trying to provide SSH access for some users, but I would like to apply application control to the rule. In rule I added SRC, DST, User Group and Port (TCP 22), then created application group, where I blocked all applications but enabled SSH Applications (did override), but users can't access to the server. But then I added to this application rule also one override rule, where select also "Canonical Ubuntu" application and then users received access.

 

But in this "Canonical Ubuntu" ( https://www.fortiguard.com/encyclopedia/iotapp/10000501 ) I see al lot of protocols (UDP, SNMP, TCP, HTTP, SSH) I need to provide access just to SSH. How I can do It. And also by best practice how do I need to create policy in such cases? 

14 replies

jsarah
Staff
Staff
July 26, 2023

may I know, why you want add application control to the policy. You can simply add service ssh to that policy.

saneeshpv_FTNT
Staff
Staff
July 26, 2023

HI,

 

You could achieve this by simply create a Firewall policy with Source, Destination and Service (as SSH-TCP22). So why would you need application control here. What are the objectives ?

 

If you still want application control, you can create a Application Profile blocking all Application category while adding SSH application to be allow as Override and then call this in the Firewall policy which is created above. 

 

Best Regards,

1mm
1mmAuthor
Explorer III
July 26, 2023

Yes, I would like to control access by Application, not just with port.

I did as you said, Created separate access control profile, blocked all application and permit just SSH. But users could not have access until I enabled also "Canonical Ubuntu" application.

saneeshpv_FTNT
Staff
Staff
July 26, 2023

Hi,

 

Fair enough, but still in the Firewall policy you only allow service TCP-22 which should restrict any other access other than port 22 for this Ubuntu Server from Layer 4 perspective and you still allowed only the respective application with application control at the Application layer. 

 

Best Regards,

 

 

1mm
1mmAuthor
Explorer III
July 26, 2023

And several additional questions:

1 - It's normal practice create an application profile, block all application categories and then enable (override) needed application (if you need to create policy based on application), correct?

2 - Why fortiget doesn't allow ssh with standard application and allowed with Canonical Ubuntu?

Are there any changes in Ubuntu for ssh? Are there some changes in SSH signatures from Ubuntu side and fortigate doesn't recognize it as "Standart" SSH? 

 

and thanks for workaround 'Block applications detected on non-default ports'."

 

@saneeshpv_FTNT Thanks for your reply, will check It. 

srajeswaran
Staff
Staff
July 26, 2023

1- is correct. General rule is block everything and allow only specific application/traffic.

2 - From your tests it looks like normal SSH and Standard SSH have some differences, but I am not sure what are the differences.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!