Skip to main content
kevanbrown
New Member
January 4, 2016
Solved

FortiOS 5.4 Internet Service Database Usage

  • January 4, 2016
  • 15 replies
  • 37749 views

While the new Internet Service Database in 5.4 is a useful reference indeed, it is frustrating that entries in it cannot be bound to firewall policies (at least not that I've found).  You have service entries in there with thousands of IP address / port combinations that would be very useful to reference in policies, whereas you would normally be required to define all of those addresses as individual address objects in the configuration.

 

Are there any plans to allow us to use this new feature in policies? Or am I just missing the way to do it currently?

Best answer by SMabille

Hi,

 

Yes if you have a valid Fortiguard subscription. However, quality can be variable depending on the service.

 

Office 365, Microsoft publish all the changes in an RSS feed at least 30 days ahead of changes so quality is excellent. 

 

On the other end of the spectrum, Netflix doesn't communicate and update are very reactive. Not a problem if you ban Netflix as the service won't be using only the additional IP and will be efficiently blocked but if you want to use it to allow and assign particular profile such as no SSL interception (as Netflix very sensitive to SSL) it's a big issue (and they keep using additional FQDN too so wildcard FQDN for exception as an alternative/top up need maintenance too).

 

Regards,

Stephane

 

mahesh p mohan wrote:

Hi

 

i have used the policy in 5.6 in one of our customer fortigate 100E and found traffic in policy. they have issue when accessing AWS service with UTM profile.

 

but i have a question . fortigate internet service database will update automatically? or not ?

if a new ip use by AWS that will update in the database?

 

 

Regards

mahesh

15 replies

MarkusM
New Member
January 6, 2016

I have to agree to that. The Internet Service Database in its current form is somewhat pointless. There is apparently (almost) nothing which can be done with the entries displayed. Currently they can only be used for static routes.

 

In example it would be convenient to have a Fortinet provided database of all Amazon networks - but only the networks as I want to specify the ports by my own.

Sylvia
Explorer
February 25, 2016

I was wondering what we can do with this internet service database, as well

 

Up to now I found that this DB is used to resolve the unknown applications (WebUI: Log&Report > Log Settings > Resolve Unknown Applications) - try the mouse-over event with the info "i".

 

Additionally it seems that you can add those services to the static routes... (CLI only)

config router static

  edit <n>

    set internet-service           # Application ID in the Internet service database. end

Unfortunately those routes don't changes anything...

 

Maybe you have more luck in configuring this...

 

Sylvia

 

Sartuche24
New Member
May 9, 2016

So I've been playing around with this feature and discovered in the CLI you can create your own Custom Entries.

 

config application internet-service-custom

 

Then go from there and design your own entries. Just thought I would pass this on. I also agree, they need to allow you to use it in Firewall Policies, if so, that would be a very powerful feature.

LGSONE
New Member
May 18, 2016

I sure hope 5.4.1 utilizes this.  I opened this one afternoon and thought great, I can add this to this policy.. was frustrating to see that after 2 hours thinking I'm missing the obvious... that is its not possible.  This would certainly be a powerful feature.

Alby23
New Member
September 9, 2016

Yeah, known problem.

By now you could only use them in policy routing in order to decide which ISP to use for each "object".

In the next releases we hope that those objects could be used in FW Policies too.

MikePruett
New Member
September 10, 2016

Fingers crossed that some new functionality comes from it soon

SMabille
New Member
November 3, 2016

Still no use in 5.4.2... Shame as a great idea but pointless until they can be used as address group (in firewall rules, SSL exception etc...)

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.