Dnscat2 not getting blocked by Firewall (Detected as Proxy Application )
Device Version: FortiGate-1500D v5.2.0,
Application control : Default policy Block Proxy
Our firewall is blocking all Proxy applications based on the policy but lately we are seeing application called Dnscat2 on FOrtianalyzer Proxy application report (SS attached) . Unlike other proxy application's which are getting blocked by firewall , this particular application is not getting blocked even though its getting identified by firewall as Dnscat2:Proxy application (Tunnels data through port 53
Hi Rajesh, it is a good idea You attach the Fg config file.
What is the src IP are you testing?
What is the Policy Id that Gf is applying?
Please capture on two CLI sessions:
1. Debug flow for that src.
2. Capture proxy detection at the same time:
dia ips share clear bt // to clear bt expect table
dia ips de en proxy
dia ips de en detect
dia de en
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.