Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
psniech
New Contributor

Blocking netflix from Microsoft Store

Application control properly blocks access to Netflix when run via browser but not blocking when Netflix is installed from Microsoft Store as an application.

2 REPLIES 2
atakannatak
New Contributor III

Hi @psniech ,


The Netflix application under the Application category is matched only with TCP/80, TCP/443, and UDP/443 ports. Specific application IDs that match Netflix are:

 

https://fortiguard.fortinet.com/appcontrol/18155
https://fortiguard.fortinet.com/appcontrol/38500
https://fortiguard.fortinet.com/appcontrol/35444
https://fortiguard.fortinet.com/appcontrol/30184
https://fortiguard.fortinet.com/appcontrol/28844


When downloading the Netflix app from the Microsoft Store, FortiGate cannot block Netflix access because I think the traffic is not web-based. However, enabling SSL deep inspection in the rules may be necessary for some application IDs to work properly. Be cautious with SSL deep inspection, as using an unreliable certificate may cause access issues with your endpoint devices.

 

Instead, you can create a URL exemption under web filter by following the article below and create a simple blocking entry for netflix.com. This way, you can restrict access at the domain level.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-The-difference-between-allow-and-exempt-in...

 

BR.

 

If my answer provided a solution for you, please mark the reply as solved it so that others can get it easily while searching for similar scenarios.

Atakan Atak
Atakan Atak
Labels
Top Kudoed Authors