Hello guys,
i stumbled into the FortiGate logs from external client which needed some analysis - ive checked the logs and there was value applist="block-high-risk" associated with public "grey area" application, but the action was action="accept" which might indicate that even the connection was flagged the connection was allowed anyway?
Can you provide more information on the Problem? It is not possible to help further with the information provided. What is the traffic flow? What do you want to achieve? What are your actual configurations?
i dont have any configuration avalaible, just logs, but ive figured it out - there is an field named utmaction= where i found that application just BitTorrent is explicitly blocked and visible, when i tried the application which i was referring before (it was Telegram) it was allowed so means that Telegram is allowed even when there is applist="block-high-risk" field in the log entry - applist="block-high-risk" seems to be default block list per documentation.
| User | Count |
|---|---|
| 2857 | |
| 1443 | |
| 823 | |
| 816 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.