Hello Fortinet Community,
I'm encountering an issue with application control on my FortiGate 60F running firmware version 7.4.8M.
Scenario:
I created a WAN access policy that allows NTP, DNS, and PING services only.
Additionally, in the Application Control profile applied to this policy, I allowed only the following applications:
All other applications are set to block.
Issue:
Despite allowing DNS in the Application Control settings, I'm seeing legitimate DNS traffic being denied in the logs. This traffic is:
It appears the firewall is misclassifying some DNS traffic as the "GitHub" application, which is not allowed by the control policy, and thus it's being blocked.
What can I do to fix this without disabling Application Control Profile.
Any insights or suggestions would be greatly appreciated.
Thank You.
Hi Sadhi
This my be app misclassification. Or can be some signature in this DNS traffic similar to GitHub app.
Does it happen only for DNS traffic from your "ubuntu-server"?
Is similar traffic from other hosts detected as GitHub app?
As a workaround try add GitHub app in the App Ctrl profile and see if it helps. Meanwhile you may open a ticket to get a clean fix.
User | Count |
---|---|
2609 | |
1390 | |
804 | |
664 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.