Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
x_member
Contributor

Blocking proxies, but permitting gotomeeting (application override?)

On a Fortigate 60D running 5.2.7 we have a somewhat basic application sensor in place to block the categories Botnet, P2P and Proxy on outbound and inbound traffic (internal - WAN)

 

I can see that this sensor is blocking the GotoMeeting app when it contacts 216.115.208.230 (egwglobal.gotomeeting.com) as Proxy.HTTP.

 

We do host and attend GoToMeeting events regularly, but I'm struggling to determine how I can permit this specific proxy usage in a simple, maintainable manner. At the moment the only way I can see to achieve this is by following these steps:

[ul]
  • duplicate the existing firewall policy.
  • specify the destination address as the FQDN egwglobal.gotomeeting.com
  • duplicate the existing application sensor and remove the Proxy category.
  • order the new firewall policy above the existing one.[/ul]

    Looking at the Application Control policies it appears that I can add specific overrides to the existing sensor based on the application signature - is there any guidance available on crafting an application signature to use as an override on the existing sensor and policy? It feels like it might be the more elegant solution here.

  • 0 REPLIES 0
    Announcements

    Select Forum Responses to become Knowledge Articles!

    Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

    Labels
    Top Kudoed Authors