Created on ‎11-14-2025 06:42 AM Edited on ‎11-14-2025 08:49 AM
Is it possible to block the Instagram app without having to block the entire QUIC protocol? I also can't enable "deep-inspection" because it will cause certificate errors for users (FortiOS 7.4.8).
Blocking Instagram reliably without deep inspection is tough, because the app shifts between QUIC, HTTPS and multiple CDN endpoints. Without SSL inspection you can use the Social Media category, but it won’t give you a 100% block rate.
Apparently, blocking port 443 over UDP solved the problem.
Hello,
Did you try blocking the Instagram Signature in the APPCTRL application override?
If you block the signature itself, the APP should be blocked by the application control profile.
Just make sure the traffic is matching the correct firewall policy.
Hope this helps!
Created on ‎11-19-2025 08:26 AM Edited on ‎11-19-2025 08:28 AM
Yes, I tried, but since the Instagram app uses QUIC, it continues to work even with Application and Filter Overrides.
| User | Count |
|---|---|
| 2803 | |
| 1425 | |
| 812 | |
| 750 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.