FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
rbarnes
Staff
Staff
Article Id 391197
Description

This article describes how to troubleshoot Application Control.

Scope FortiGate, FortiProxy.
Solution

Check the logs to see if the Application is being detected.

 

Log and Report:

Go under Security events -> Logs, select Antivirus, drop it down, and choose 'Application Control'.

 

Here is an example:

 

appcontrol1.png

 

For more information on how to filter traffic logs: Technical Tip: How to apply filters in forward traffic logs

 

If the application is not shown in the logs, add the specific app to the app control profile under Security Profiles -> Application Control. Under applications and filters, select 'Create New'.

 

Example:

 

appcontrol2.png

 

appcontroladdsig.png

 

Select the application:

 

'Right-click' the application and select Add Selected. If this does not help, and there are no logs for the signature, enable the deep scanning feature on the policies: Technical Tip: How to enable Deep Content Inspection

 

Some applications will not need deep scanning. This will be listed in the description. If the application is not in the application in the logs.

 

A form can be submitted to the FortiGuard team to fix the Application Control signature: Application Control Submission Form | FortiGuard Labs

 

When submitting the form, it is recommended to include logs and packet capture of the traffic.

 

 

Note: 

In order to test and verify that application control is working as expected, it is recommended to create a profile with all signatures and categories in the monitor state.