Skip to main content
jeskudero
New Member
November 26, 2018
Solved

Industrial category is missing

  • November 26, 2018
  • 7 replies
  • 17322 views
Hello   I have a 60E and i recently have updated to fortiOS 5.6.6 from 5.4. Before the update i could find the industrial category in the app control section to block specific industrial traffic but in fortiOS5.6 this category is missing and i cant configure the fortigate to block this kind of traffic. The fortinet documentation says that industrial protocols are enabled to be identified (https://fortiguard.com/appcontrol?category=Industrial&deepapp=&page=1)   Thanks
Best answer by jeskudero

Hello

It seems like Fortinet has exclude the industrial signatures from the UTM license group, you hava to purchase those signatures apart of the UTM license or you have to purchase the enterprise licecense. That was my local seller response.

 

anyway, thanks for your responses!

7 replies

Dave_Hall
New Member
November 26, 2018

Not familiar with 5.6, so it may be possible that the category is still there, though renamed or recategorized.   You could always check via the CLI, just perform something similar to:

 

config application list edit "default" config entries edit 1 set category ?

At ?, the fgt should output something similar to:

 

ID           Select Category ID 1            IM 2            P2P 3            VoIP 5            Video/Audio 6            Proxy 7            Remote.Access 8            Game 12           General.Interest 15           Network.Service 17           Update 19           Botnet 21           Email 22           Storage.Backup 23           Social.Media 24           File.Sharing 25           Web.Others 26           Industrial 27           Special 28           Collaboration 29           Business 30           Cloud.IT 31           Mobile

bommi
New Member
November 26, 2018

Hi,

 

if you want to use the industrial services signatures you need to do this:

 

config ips global

set exclude-signatures none

end

Regards

bommi

jeskudero
jeskuderoAuthor
New Member
November 27, 2018

Hi

 

bommi, i have already tried that solution but it doesnt work. (https://forum.fortinet.com/tm.aspx?m=169179)

 

Dave hall, i have done what you said and it shows me the list like you put there. I have selected the industrial category but then it doesnt show me in the GUI, and I cant find the industrial signatures (modbus write and read for example).

 

I have tried to reboot several times but nothing happens, this is how i have the config now:

 

FGT60EXXXX # config vdom FGT60EXXXX (vdom) # edit root current vf=root:0 FGT60EXXXX (root) # config application list FGT60EXXXX (list) # edit Trafico\ industrial FGT60EXXXX (Trafico industrial) # config entries FGT60EXXXX (entries) # show config entries     edit 1         set category 26         set application 25890 25900 44542     next     edit 2         set category 2 3 5 6 7 8 12 15 17 21 22 23 25 26 28 29 30 31     next end

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!