FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
pginete
Staff
Staff
Article Id 229072
Description This article describes how to allow or deny specific applications using the application service.
Scope FortiGate.
Solution

FortiGate should be set up in explicit proxy to allow specific applications to use the application service.

 

  1. Make Sure the Explicit Proxy is enabled for visibility in the GUI, using the below command:


config system settings
    set gui-proxy-inspection enable
end

 

  1. After enabling, navigate to System -> Feature Visibility, then under Security Feature, enable explicit Proxy.


Capture-2.PNG

 

  1. Go to Policy & Objects -> Services, select Create New, then Service. Enable Application Service. Select the desired application to be allowed or denied. It is also possible to allow or deny specific application categories. Configure the destination port of the application.

 

pginete_0-1667809658584.png

 

  1. Select the application service under Service of the policy under Policy & Objects -> Proxy Policy.

 

pginete_1-1667809721090.png

 

Note: