Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Sadhi_Jayz
New Contributor III

Application Control Misidentifying DNS Traffic

Hello Fortinet Community,

 

I'm encountering an issue with application control on my FortiGate 60F running firmware version 7.4.8M.

Scenario:

I created a WAN access policy that allows NTP, DNS, and PING services only.

 

4.png

 

Additionally, in the Application Control profile applied to this policy, I allowed only the following applications:

  1. NTP
  2. DNS
  3. PING

All other applications are set to block.

5.pngIssue:

 

Despite allowing DNS in the Application Control settings, I'm seeing legitimate DNS traffic being denied in the logs. This traffic is:

  • Port: 53 (UDP)
  • Destination: 8.8.8.8 (Google DNS)
  • Action: Denied
  • Detected Application: GitHub

1.png

 

2.png

 6.png

 

3.png

 

It appears the firewall is misclassifying some DNS traffic as the "GitHub" application, which is not allowed by the control policy, and thus it's being blocked.

 

What can I do to fix this without disabling Application Control Profile.

Any insights or suggestions would be greatly appreciated.

 

Thank You.

1 REPLY 1
AEK
SuperUser
SuperUser

Hi Sadhi

This my be app misclassification. Or can be some signature in this DNS traffic similar to GitHub app.

Does it happen only for DNS traffic from your "ubuntu-server"?

Is similar traffic from other hosts detected as GitHub app?

As a workaround try add GitHub app in the App Ctrl profile and see if it helps. Meanwhile you may open a ticket to get a clean fix.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors