Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kaorin
New Contributor

False possitive of eDonkey ?

Dear all I have a FG3040B box running with FortiOS 4.0 MR2 Pathc10(AV, DLP and WebFilter are not licensed). I want to block all P2P application traffice except Skype, Skype.Communication, I set the P2P application filters and apply them to the firewall policy correctly. These days,I noticed strange behavior of FG3040B box. IMAPS and Skype traffics are blocked by IPS signature as " eDonkey" ,sometimes even HTTP and HTTPS blocked,too. Surely,some internal users are banned and blocked with IMAPS, Skype(and HTTP, HTTPS) and logged as " eDonky" in same time. I run the debug command to get diagnostic information, but in vain. That made FG304B box freezed only(FG3040B box is running under the heavy traffic. Many restiriction rules of IPS, IDS may caused ? ) So I can not still open the case in TAC. Is this a false possitive signature of " eDonkey" ? I' m sure that the signature of " eDonkey" is spoiled. If so, what can I do ? I lost my way. Best regards
== kaorin
== kaorin
3 REPLIES 3
sfales
New Contributor II

I have a similar problem. I enabled app-control to block Botnets only. The next day I have users that cannot log on to the domain. It appears that the FG is detecting UDP88 (Kerberos) as eDonkey, and blocking it. I have opened a support ticket for this.
(4) - 200b' s (15) 81WiFi FAZ 400b Fmgr 100c
(4) - 200b' s (15) 81WiFi FAZ 400b Fmgr 100c
Sumanth_FTNT

Dear All, I am currently using 4.0 MR3 & i am not seeing this issue, tried with IMAPs & all other skype communication. Might be there is FP signature by eDonkey in older versions.
Joe62
New Contributor

Hello, we found a similar problem as described by sfales: microsoft authentication kerberos traffic is sometimes detected as eDonkey protocol and blocked by our application control rules (FGT 1000A with release MR3 patch10). We had to create an exception rule to avoid this blocking that was causing a slowdown of the clients operation. Before to open a ticket, did you have some useful answer from the technical support ? Thanks Regards
Labels
Top Kudoed Authors