Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
damianhlozano
Contributor II

Application control is not blocking browsers

Hello team!!!

 

My boss asked me to block Internet access for Firefox and Opera browsers in a Fortigate 60F :( with version 7.6.4

In an application control, which is like the "default" (All categories as "Monitor"), I added an application override, to block the following apps:

* HTTP.BROWSER_Opera

* HTTP.BROWSER_Opera.Mini

* Opera.Turbo

* Opera.Update

* Opera.VPN

* Firefox.Update

* HTTP.BROWSER_Firefox

 

(All applications found with the words "Opera" and "Firefox")

I applied the application control to a policy for the test machine, and when I tested, I still could use any browser.

The policy has applied the default "certificate-inspection" profile as "SSL Inspection"

Does this needs to use full inspection?

Do you know why both browser are still working?

Is there another way to block these browsers from the Fortigate?

 

I know this is better to block the application from the computer or from a centralized solution, but I need to know if is this possible to accomplish this with the Fortigate

 

Thanks in advance.

Regards,

Damián

 

Damián Lozano
Damián Lozano
2 REPLIES 2
RBA
Staff
Staff

Hello,

I would suggest using policy in proxy inspection mode with deep inspection enabled. Application control and IPs profile can be applied to block the signatures. 

 

damianhlozano

Thanks RBA,

I will try to find out how to set the policy in proxy inspection mode with 7.6.4

I also will try with and without full inspection, but we cannot use deep inspection here.

I will tell you later

 

Regards,

Damián

Damián Lozano
Damián Lozano
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors