Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rak
New Contributor

App Store iOS not updateing Apps

Hello, I am one of the new kids in the block with a FG 40C. Everything works so far. I encountered trouble when updating apps with the iOS App Store. Programms will not load since UTM is active. When I turn of UTM in the respective policy it works. I had yet not the chance to dig deeper into the problem and turn on/off every UTM service to find the guilty one. Can someone hint me in the right direction? Would be much appreciated. Kind regards. Ralf
7 REPLIES 7
Dave_Hall
Honored Contributor

You can enable access to the iTunes/apple store via the App control sensor section of the UTM that is applied to the firewall rule. You may need to check the utm logs to see what exactly needs to be unblocked.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
rak
New Contributor

Thanks Dave for the swift reply. Just to ensure I got it right. [ul]
  • You propose to create a new application sensor with a new application filter allowing the appstore traffic and blocking everything else.
  • Then I need to create a new policy between internal and wan which uses exactly this application sensor in UTM enable application control.
  • This policy must be above the normal WAN policy [/ul] This would ensure that appstore traffic is catched by this policy and all other traffic is blocked? I have a question mark here (I am new to firewalling, sorry). Wouldnt that mean that all traffic applies to this policy and only the appstore traffic would go through. All other traffic is using also this policy, beeing blocked b the app controll and not reaching the sencond policy allowing the normal traffic? Appreatiate some guidance here. Thanks a lot.
  • rak
    New Contributor

    One additional comment. I have not blocked any apps in the app sensor at all currently. Everything is monitored only (all other known and unknown).
    Dave_Hall
    Honored Contributor

    Under 4.0 MR3 you just add an entry to the existing app sensor that allows access to iTunes/Apple Store. I am assuming you have UTM enabled on a firewall policy with an app sensor -- this app sensor can hold entries for apps you want to block or allow. You stack whatever apps you want to allow/block into this app sensor. (Note like firewall policies -- app sensor entries are applied from top-to-bottom.) (Not really familiar with 5.0 enough to know the exact steps in that firmware to add the app sensor, but it should be similar. ) There is no need to create new firewall policies unless you have something specific in mind or want to optimize/streamline your config. If you want to learn more about Fortinet/Fortigates you should check out the Cookbook.

    NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

    NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
    Dave_Hall
    Honored Contributor

    I have not blocked any apps in the app sensor at all currently. Everything is monitored only (all other known and unknown).
    Check the UTM logs (if enabled) to see what is being blocked. Perhaps all you need is a URL filter that allows access to *.apple.com,

    NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

    NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
    Rick_H
    New Contributor III

    While you' re eyeballing your logs, check your antivirus logs on the FGT. I had some random AV hits when attempting downloads from the iTunes store a few days ago.
    rak
    New Contributor

    Hello, thanks fro your time and effort so far. I have 4.0MR3, logs are empty, especially antivir log. Yes logs are enabled. Not all, but only some apps are effected when updating. This hints to false positives in Antivir scanning. I changed from Proxy to Flow based and the update works now. Can this be a memory issue on the FG? Dashboard shows 62% memory usage. I have a 40C and running it in my private environment. So no heavy commercial usage. Just a bit of web browsing and other stuff you have in a household with 40+ IP addresses ,-). Kind regards. Ralf
    Announcements

    Select Forum Responses to become Knowledge Articles!

    Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

    Labels
    Top Kudoed Authors