I have problems with a policy where I include an application control where I block access to facebook, youtube and others, one of the applications that I allow within the control is whatsapp but it has presented problems since yesterday, the attached files are not They send and the messages are sent several minutes later, the same as when receiving.
I have been doing tests and by allowing the known applications the whatsapp starts working correctly, someone could help me know what the problem is if everything was working well until yesterday that I present this inconvenient.
My device is a Fortigate 90D
The only categories that I have blocked in the control of applications are: Botnet, Game, P2P, Social.Media, Update, Video/Audio and Unknown applications (now in monitor mode for whatsapp work)
I received the below feedback earlier today on my ticket I logged with Fortinet;
We have released improved WhatsApp signature in IPS definition version 12.315, please update the IPS definition to latest version and test again.
If the traffic about WhatsApp still detected as Facebook-Web in Forward Traffic log , please provide us a full packet capture which include the traffic, thanks.
I upgraded our IPS definition package to the latest version (12.315) and customer has confirmed it is working again with no issues. I've checked the logs, and the destinations where we were getting blocked (e6.whatsapp.net, e14.whatsapp.net, etc) which was classified as 'Facebook-Web' application traffic in the 'Unknown Applications' category, is now being seen as 'WhatsApp' application traffic within the 'Collaboration' category, which is correct.
Will continue to monitor and will revert if we pick up any issues.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.