Skip to main content
TheGorf
New Member
November 25, 2025
Question

How much of an Applcation Control profile includes urls?

  • November 25, 2025
  • 2 replies
  • 235 views

I've been building some policies to control egress and I came across and interesting situation. I was building a policy for Apt (apt-get). And it works perfectly fine. Except for when a server has an additional repository installed. These are all Debian 12. And everything works except for when the Docker repos refresh. In which case Apt starts getting back 403's and 401s. Toggling the policy on and off directly affects whether Apt works correctly or not. 

 

So, I'm trying figure out if this is my outbound SSL inspection policy meddling with a pinned cert or something I need to modify in my policy. 

 

Thanks all for the thoughts on this.

2 replies

akutsage1
New Member
November 25, 2025

I don't think there's any such thing as precedence. If you have both enabled then they must both permit the traffic for it to be allowed. If the WF permits but AC blocks then the session is blocked.

AEK
SuperUser
SuperUser
November 25, 2025

What do you see in the related FGT's deny traffic log? It should provide the detailed reason for which it has denied the traffic. Check also the security log in the related deny traffic log, to see which security profile has denied it and why.

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!