FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
emalayan
Staff
Staff
Article Id 345670
Description

This article describes that if the Application Control Definitions are up-to-date on FortiGate and the specific application that is looking for is not in the list of Application Signatures under Security Profiles -> Application Signatures, there is no result for the application when a lookup  is processed via https://www.fortiguard.com/services/appcontrol is

 

Scope FortiGate.
Solution

Submit Application Control Submission form via the following FortiGuard website: https://www.fortiguard.com/faq/appctrlsubmit

 

2024-09-30 13 23 31.png

 

After submitting the request, the FortiGuard team will send an email. Note that the FortiGuard team may request packet capture for the application. Before submitting the request, it is advised to do a packet capture for the application by performing the following:

  1. Close application completely. To avoid capturing unnecessary traffic from other applications, please also to close other running applications
  2. Connect to FortiGate CLI and turn on logging in the client (SSH, telnet, putty or console). For putty, the this below KB article: Technical Tip: How to create a log file of a session using PuTTY
  3. Type 'diagnose sniffer packet <interface_name> 'host <device IP address>' 6 0 l'.
  4. Start the application and and perform some basic operations using the application.
  5. After capturing traffic, press ctrl-c to stop the sniffer.

 

Related document:

Creating IPS and application control signatures

Contributors