Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kelv1n
New Contributor

Application Control option "Replacement Messages for HTTP-based Applications" and HTTPS?

Hi Guys

 

I've configured an Application Control sensor, switched on the Replacement message, enabled deep-packet inspection etc and blocked GMail - but rather than getting a nice "This is blocked" message, the browser receives nothing.

 

Does the Replacement Messages not work with HTTPS traffic, even with Deep Packet inspection on?

 

Thanks

2 REPLIES 2
marsmatt
New Contributor

*Bump* 

 

I was wondering the same thing? Any information on this? I'm having trouble getting a concrete answer. 

 

Thanks

tanr
Valued Contributor II

Which version of FortiOS are you running?

If you're running 5.4.x, is the FortiGate in flow mode or proxy mode?

App Control is run in flow mode regardless of whether the FortiGate is in "proxy" mode.

What other profiles are on the security policy?

 

Per the FortiOS documentation, you can run into problems with replacement messages not showing up if your policy has a proxy-mode Web Filter along with the (flow-mode) App Control.

 

My recent tests of this in 5.4.1 and 5.4.2 showed the replacement messages getting through properly, even with this configuration, but that doesn't guarantee it will work in all cases.  Discussion of this is in this post: https://forum.fortinet.com/tm.aspx?m=135666&mpage=2.

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors