Skip to main content
sponsz
New Member
March 12, 2021
Question

NGFW policy-based mode not blocking traffic

  • March 12, 2021
  • 0 replies
  • 2149 views

Hello,

I am running a Fortigate 40F in policy-based mode and see a behaviour that I don't understand:

I have configured only two policies:

 

1. Block all traffic/any app id to url categories (spam, phishing etc.)

2. Allow traffic only with app id HTTPS.BROWSER

 

From my traffic logs I can see that sometimes first HTTPS.BROWSER and then another app id is recognized, but the traffic is not blocked.

For example when browsing github.com the first log entry from app-ctrl is HTTPS.BROWSER and the next entry is Github which is not allowed by policy. The forwading log entry at the end of the session states Github too, but browsing was not blocked.

I have seen this behaviour with traffic to skype and adobe too.

 

 

 

Should not the firwall block this traffic when a not allowed app id is seen in a session?

Is that because NGFW in policy-based mode is doing only flow-mode and not proxy-mode?

 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!