FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
SimranRana
Staff
Staff
Article Id 395377
Description This article describes an issue where reputable sites such as WhatsApp, Facebook, Instagram, etc., do not get blocked via the Deep Inspection profile.
Scope FortiGate, Application Control, SSL/SSH Inspection Profile.
Solution

For blocking access to applications such as WhatsApp, either for all users or specific groups, an Application Control policy can be created as shown below:

 

Firewall Policy:

 

KB1.png

 

Application Control Security Profile:

 

KB2.png

 

Some application signatures require SSL Deep Inspection.

 

KB3.png

 

After switching to a Custom Deep inspection profile, reputable sites such as WhatsApp might start getting allowed:

 

KB4.png


KB5.png


This can be due to the following option in the Custom Deep Inspection Profile (disabled on the deep-inspection profile):

 

KB6.png

 

As WhatsApp, Instagram, Facebook, etc., are reputable sites as per the Rating by FortiGuard, these will be exempted from SSL Inspection and therefore will start getting allowed.

KB10.png

 

This can be verified for any site that gets allowed unexpectedly after assigning Deep inspection by enabling 'Log SSL exemptions' and checking Logs & Reports -> Security Events -> Logs -> SSL:

 

KB8.png

 

KB7.png

 

By disabling the 'Reputable websites' option in 'Exempt from SSL Inspection', sites will not be exempted, and the security profiles will be applied as expected.

 

Ensure to check the category as well, along with the addresses in the exempt list. If required, remove the category and just add addresses in the exempt list.

 

KB9.png

 

Related article:
Technical Tip: Information on 'Reputable web sites' for SSL inspection