Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kevanbrown
New Contributor

FortiOS 5.4 Internet Service Database Usage

While the new Internet Service Database in 5.4 is a useful reference indeed, it is frustrating that entries in it cannot be bound to firewall policies (at least not that I've found).  You have service entries in there with thousands of IP address / port combinations that would be very useful to reference in policies, whereas you would normally be required to define all of those addresses as individual address objects in the configuration.

 

Are there any plans to allow us to use this new feature in policies? Or am I just missing the way to do it currently?

1 Solution
SMabille

Hi,

 

Yes if you have a valid Fortiguard subscription. However, quality can be variable depending on the service.

 

Office 365, Microsoft publish all the changes in an RSS feed at least 30 days ahead of changes so quality is excellent. 

 

On the other end of the spectrum, Netflix doesn't communicate and update are very reactive. Not a problem if you ban Netflix as the service won't be using only the additional IP and will be efficiently blocked but if you want to use it to allow and assign particular profile such as no SSL interception (as Netflix very sensitive to SSL) it's a big issue (and they keep using additional FQDN too so wildcard FQDN for exception as an alternative/top up need maintenance too).

 

Regards,

Stephane

 

mahesh p mohan wrote:

Hi

 

i have used the policy in 5.6 in one of our customer fortigate 100E and found traffic in policy. they have issue when accessing AWS service with UTM profile.

 

but i have a question . fortigate internet service database will update automatically? or not ?

if a new ip use by AWS that will update in the database?

 

 

Regards

mahesh

View solution in original post

15 REPLIES 15
mahesh_secure

Hi

 

i have used the policy in 5.6 in one of our customer fortigate 100E and found traffic in policy. they have issue when accessing AWS service with UTM profile.

 

but i have a question . fortigate internet service database will update automatically? or not ?

if a new ip use by AWS that will update in the database?

 

 

Regards

mahesh

SMabille

Hi,

 

Yes if you have a valid Fortiguard subscription. However, quality can be variable depending on the service.

 

Office 365, Microsoft publish all the changes in an RSS feed at least 30 days ahead of changes so quality is excellent. 

 

On the other end of the spectrum, Netflix doesn't communicate and update are very reactive. Not a problem if you ban Netflix as the service won't be using only the additional IP and will be efficiently blocked but if you want to use it to allow and assign particular profile such as no SSL interception (as Netflix very sensitive to SSL) it's a big issue (and they keep using additional FQDN too so wildcard FQDN for exception as an alternative/top up need maintenance too).

 

Regards,

Stephane

 

mahesh p mohan wrote:

Hi

 

i have used the policy in 5.6 in one of our customer fortigate 100E and found traffic in policy. they have issue when accessing AWS service with UTM profile.

 

but i have a question . fortigate internet service database will update automatically? or not ?

if a new ip use by AWS that will update in the database?

 

 

Regards

mahesh

Alby23
Contributor II

Yeah, known problem.

By now you could only use them in policy routing in order to decide which ISP to use for each "object".

In the next releases we hope that those objects could be used in FW Policies too.

MikePruett
Valued Contributor

Fingers crossed that some new functionality comes from it soon

Mike Pruett Fortinet GURU | Fortinet Training Videos
SMabille

Still no use in 5.4.2... Shame as a great idea but pointless until they can be used as address group (in firewall rules, SSL exception etc...)

pcraponi

SMabille wrote:

Still no use in 5.4.2... Shame as a great idea but pointless until they can be used as address group (in firewall rules, SSL exception etc...)

It's already done in 5.6 code... Will be available on Beta 2...

 

 

Regards, Paulo Raponi

Regards, Paulo Raponi
Labels
Top Kudoed Authors