Device Version: FortiGate-1500D v5.2.0,
FortiAnalyzer v5.2.2
Application control : Default policy Block Proxy
Our firewall is blocking all Proxy applications based on the policy but lately we are seeing application called Dnscat2 on FOrtianalyzer Proxy application report (SS attached) . Unlike other proxy application's which are getting blocked by firewall , this particular application is not getting blocked even though its getting identified by firewall as Dnscat2:Proxy application (Tunnels data through port 53
http://fortiguard.com/appcontrol/app-41612
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi Rajesh,
If required, the Dnscat2 signature can be set to "Block" to block this application using app control.
jintrah wrote:thanks for reply but i alrdy checked that , Dnscat2 is coming under category Proxy and its blocked in my policies .still Dnscat2 is not getting blockedHi Rajesh,
If required, the Dnscat2 signature can be set to "Block" to block this application using app control.
Hi Rajesh, it is a good idea You attach the Fg config file. What is the src IP are you testing? What is the Policy Id that Gf is applying? Please capture on two CLI sessions: 1. Debug flow for that src. 2. Capture proxy detection at the same time: please use: dia ips share clear bt // to clear bt expect table dia ips de en proxy dia ips de en detect dia de en
Yamidt
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1536 | |
1029 | |
749 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.