Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
GLOBAL
New Contributor

Application Control not detecting upload signature

Hello Friends!

I recently upgrade to a 600F at 7.0.12 and now my Application Control for Google Drive is not detecting the right upload signature. Hence it is not blocking upload. All worked fine with a 300E at the same firmware version.

 

SensorFWUSR-ADM-INTERMEDIARIO-GOOGLE
Application NameGoogle.Drive
ID32121
CategoryStorage.Backup
Risk
 
 
 
 
 
Protocol6
ServiceHTTPS
MessageStorage.Backup: Google.Drive

The upload show as just Google.Drive and the action is pass (correct for the miss identified signature).

Actionpass
Policy IDOUTBOUND FWUSR-ADM-INTERMEDI-GOOGLE (1107)
Policy UUIDab55ec0e-743b-51ee-54db-38c3dc4c64df
Policy Type

Firewall

It righlty detects the download signature.

SensorFWUSR-ADM-INTERMEDIARIO-GOOGLE
Application NameGoogle.Drive_File.Download
ID35434
CategoryStorage.Backup
Risk
 
 
 
 
 
Protocol6
ServiceHTTPS
Application User 
Cloud Actiondownload
Message

Storage.Backup: Google.Drive_File.Download

Web filter category for File Sharing and Storage is monitor. Application control Storage is also monitor. And the necessary signature for Drive.Upload are block. An i have triple check and it is using deep-inspection with out insenting google drive from inspection.

Any known bug in 7.0.12?

2 REPLIES 2
abarushka
Staff
Staff

Hello,

 

I would recommend to double check whether blocking signature is above allow signature (only visible in CLI):

 

config application list
edit <>
config entries
edit 1
set category <>

set action block
next
edit 2
set action pass
next
end
next
end

FortiGate
GLOBAL

Hello, checked, it is double blocked even:

ac drive upload.PNG

It just happened to come to my attention that Google.Docs.Edit was wrongly blocked on this same group "INTERMEDIARIO-GOOGLE'. And sure, there is was (on the picture above already removed) on blocked. And it was identified correclty, just the upload seams to be broken for me for some reason.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors