Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Bigdog
New Contributor

Application Control - cloudflare Warp getting through Firewall

I have a question regarding blocking the Cloud flare warp app on our application control in the firewall settings.

I have blocked all proxys and VPN's in the generic filters and the app is inside those blocks. However the app still seems to run and bypass all filtering on the firewall. When I run a scan I can see that the app is working and bypasses the application control settings.

Anyone know what this problem?
Is it a tunnelling problem or a port?
I can see it uses the MASQUE protocol.

Bigdog - Sys Admin
Bigdog - Sys Admin
2 REPLIES 2
Anthony_E
Community Manager
Community Manager

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Yurisk
SuperUser
SuperUser

Reading the Fortinet docs about  this - they recommend to block Cloud Warp access by IP address blocks, I can deduct that Fortinet yet to come up with an effective AppControl signature to block it. 

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-Block-Cloudflare-WARP/ta-p/213214

 

CloudFlare Warp ranges from Cloudflare docs: https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/deployment/firewal...

 

Also, I'd think if you had white-listed ports only allowed, like 80/443/etc and block every other port, enforcing protocol adherence in profile, it would potentially block it as it is some MASQUE protocol tunneled inside HTTPS and FGT usually has no problem with detecting such, provided you have Deep SSL Inspection.

https://yurisk.info
https://yurisk.info
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors