Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
istro_jp
New Contributor II

Fortigate block-high-risk applist gets accepted anyway

Hello guys,

 

i stumbled into the FortiGate logs from external client which needed some analysis - ive checked the logs and there was value applist="block-high-risk" associated with public "grey area" application, but the action was action="accept" which might indicate that even the connection was flagged the connection was allowed anyway?


2 REPLIES 2
Demir25
New Contributor III

Can you provide more information on the Problem? It is not possible to help further with the information provided. What is the traffic flow? What do you want to achieve? What are your actual configurations?

istro_jp
New Contributor II

i dont have any configuration avalaible, just logs, but ive figured it out - there is an field named utmaction= where i found that application just BitTorrent is explicitly blocked and visible, when i tried the application which i was referring before (it was Telegram) it was allowed so means that Telegram is allowed even when there is applist="block-high-risk" field in the log entry - applist="block-high-risk" seems to be default block list per documentation.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors