Skip to main content
ZAHIDHASEEB
Visitor III
May 3, 2023
Question

We want to allow MS Teams from a top Firewall Rule

  • May 3, 2023
  • 6 replies
  • 7561 views

We want to allow MS Teams from a top Firewall Rule and to allow other applications I want to forward the request to other Firewall rules instead of denying immediately  

6 replies

AlexC-FTNT
Staff
Staff
May 3, 2023

Hello!

I am not sure how you would like to achieve that in a FortiGate.

Once the policy is matched, the application control will give the verdict : either allow(monitor) or deny. There is no configurable action to pass the scanning to another policy, because this has already been matched

ZAHIDHASEEB
Visitor III
May 3, 2023

Actually I am facing a lot disconnection sometimes on MS Teams and now think that I should allow only Teams without applying any AV, IPS or other Security Profile on Firewall Rule for MS Teams.

In short I don't want to apply any Security Profile against only MS Teams application

AlexC-FTNT
Staff
Staff
May 3, 2023

Understood now. Check if this App Control profile helps as TOP policy.

You can also deny MSTeams in all previous policies, and use this as a bottom policy.

(deep inspection may be required)

App control profileApp control profile

Cajuntank
Contributor III
May 3, 2023
gfleming
Staff
Staff
May 3, 2023

You can't use app control profiles to globally restrict access to applications.

You'll probably need to use ISDB instead of app control here...

 

But also it might be better if you can give us more details as to what exactly you are trying to accomplish?

Christian_89
Contributor III
May 3, 2023

You can enable Internet Service in the Top Rule with all MS-TEAMS service.

 

AlexC-FTNT
Staff
Staff
May 4, 2023

ISDB is the best approach as long as this identifies correctly all MS.teams IPs.isb.png

Christian_89
Contributor III
May 4, 2023

Is this solution enough for you or do you still need help?