Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.

CamrEntr
New Contributor

FortiClient5.4 (Registered to FCTEMSv1.0) blocking "PowerShell" with A.D module.

My FortiClient5.4 (Registered to FCTEMSv1.0) Application Firewall is blocking "PowerShell" with A.D module as "BitTorrent".  Anyone else experiencing this issue?

11/23/2015 5:27:24 PM        Notice Firewall         date=2015-11-23 time=17:27:24 logver=2 type=traffic level=notice sessionid=27436072 hostname=TEST_LAPTOP uid=0E67C2DEC0A44900B3869AB2B07B3AE4 devid=FCT8000831212723 fgtserial=FCTEMS3425844176 regip=N/A srcname=powershell.exe srcproduct="Microsoft® Windows® Operating System" srcip=10.2.10.117 srcport=57022 direction=outbound destinationip=10.2.3.5 remotename=N/A destinationport=9389 user=me@MYDOMAIN.com proto=6 rcvdbyte=N/A sentbyte=N/A utmaction=blocked utmevent=appfirewall threat=BitTorrent vd=root fctver=5.4.0.0780 os="Microsoft Windows 10 Professional Edition, 64-bit (build 10586)" usingpolicy="IT_Laptops" service= url=N/A userinitiated=0 browsetime=N/A

5 REPLIES 5
KM_FTNT
Staff
Staff

We will investigate this issue. thanks


Technical Videos - video.fortinet.com
Technical Docs - docs.fortinet.com

Technical Video - video.fortinet.com

Technical Docs - docs.fortinet.com

 

CamrEntr

Just wondering if there are any updates to this.  I'm still unable to use MS PowerShell at the moment.

KM_FTNT

Can you check the "engine > application" version under the about page on FortiClient.  What version is it running ? 


Technical Videos - video.fortinet.com
Technical Docs - docs.fortinet.com

Technical Video - video.fortinet.com

Technical Docs - docs.fortinet.com

 

CamrEntr

Application: 3.00128

KM_FTNT

Next IPS Engine update should fix this issue (not sure fo the ETA yet). thanks


Technical Videos - video.fortinet.com
Technical Docs - docs.fortinet.com

Technical Video - video.fortinet.com

Technical Docs - docs.fortinet.com