Hi,
We have Fortigate 60E in our network. I tried to block facebook chat and videos while allowing facebook which didn't work. All the users are accessing facebook through web i-e //https. I have done settings in 'Application Control' where i have added Application Signature for facebook Chat & Videos = Block. But it's not working. What other configuration or settings are required to Block only Facebook Chat and Videos? Need your kind response. Thank You
Regards,
Asim Raza
Technical Consultant/Network Security
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi Asim,
Usually, you don't need anything else, just enabling the App Control on the policy. Can you send a screenshot of your Application Control configuration? Otherwise, with version 5.4, there is the CASI (Cloud Access Security Inspection) feature that can be useful to you.
BR
Bubu
Bubu
Hi BABU,
I have Fortigate 60E, Firmware V5.6.2. I have done the required basic settings in Application Control like FB is allowed and in Application Signature only FB Chat & Videos are BLOCKED. In Web Filtering i didn't change anything. Now you are saying you have to enable CASI, which i can't see in Fortigate Security Profiles. How can i enable it then when it's not available in Fortigate. I have checked that in Feature Visibility too where you can get the required feature you want to enable. Any idea what can be done ?
Thank You
Regards,
Asim Raza
Technical Consultant/Network Security
1. Check which policy is used when you browse facebook.com diagnose debug flow filter saddr "source address" diagnose debug flow filter dport "destination port 443" diagnose debug enable diagnose debug flow trace start 30
Browse to facebook.com from your source address diagnose debug disable diagnose debug flow trace stop Check which policy is used (policy_id)
OR
Policy & Objects > IPv4 Policy > Policy Lookup
OR
Check your forward logs
If it's the right policy, it means you have a problem with App Control. This will save you looking elsewhere.
Bubu
Hello Asim,
You need to enable SSL deep-inspection to use the Facebook_Chat and Facebook_Video signatures properly since they are HTTPS.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1714 | |
1093 | |
752 | |
447 | |
232 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.